VU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers
Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pages/chat/control.py` that load a Conversation record by its ID without comparing the requester's `user_id` to the conversation's owner `Conversation.user`. This allows any authenticated user to perform the following actions: 1. Read other user's chat transcripts, RAG retrieval history, AI-generated plots, and chat suggestions. 2. Permanently delete another user's conversation. 3. Rename another user's conversation. 4. Overwrite another user's conversation's chat suggestion list.
AI Analysis
Technical Summary
Cinnamon's Kotaemon (all versions up to v0.12.0) fails to verify conversation ownership in its multi-user chat interface. The affected handlers (select_conv, delete_conv, rename_conv, persist_chat_suggestions) query conversations by ID without ensuring the conversation belongs to the requesting user. This allows any authenticated user to read full chat transcripts, retrieval histories containing verbatim excerpts from private documents, rename conversations, overwrite chat suggestions, or delete conversations permanently. Conversation UUIDs are exposed via the global conversation browser and remain valid even if conversations are later set to private. The persist_chat_suggestions handler can be abused to inject attacker-controlled prompts, potentially influencing the AI model. There is no recycle bin or soft-delete, so deletions are permanent. The vulnerability is an IDOR (Insecure Direct Object Reference) affecting confidentiality, integrity, and availability.
Potential Impact
The vulnerability allows disclosure of full chat transcripts and retrieval histories containing sensitive document excerpts, violating confidentiality. Attackers can permanently delete any conversation, impacting availability. Integrity is compromised by renaming conversations and injecting attacker-controlled prompt suggestions, which may influence AI behavior. No elevated privileges are required; any authenticated user can exploit this. The exposure of UUIDs through public conversation listings facilitates exploitation. The lack of soft-delete means deleted conversations cannot be recovered. This is particularly impactful in enterprise environments where proprietary documents are indexed and queried.
Mitigation Recommendations
No official patch or fix is currently available as the vendor could not be reached for coordination. Users should monitor the vendor's GitHub repository and official website for future updates and patches. Until a fix is released, restrict authenticated user access to trusted parties only and consider additional access controls or network segmentation to limit exposure. Review and audit conversation UUID exposure in public listings to reduce risk. Avoid using Kotaemon in multi-user mode in sensitive environments until the issue is resolved.
VU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers
Description
Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pages/chat/control.py` that load a Conversation record by its ID without comparing the requester's `user_id` to the conversation's owner `Conversation.user`. This allows any authenticated user to perform the following actions: 1. Read other user's chat transcripts, RAG retrieval history, AI-generated plots, and chat suggestions. 2. Permanently delete another user's conversation. 3. Rename another user's conversation. 4. Overwrite another user's conversation's chat suggestion list.
Affected software
pkg:github/cinnamon/kotaemonRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cinnamon's Kotaemon (all versions up to v0.12.0) fails to verify conversation ownership in its multi-user chat interface. The affected handlers (select_conv, delete_conv, rename_conv, persist_chat_suggestions) query conversations by ID without ensuring the conversation belongs to the requesting user. This allows any authenticated user to read full chat transcripts, retrieval histories containing verbatim excerpts from private documents, rename conversations, overwrite chat suggestions, or delete conversations permanently. Conversation UUIDs are exposed via the global conversation browser and remain valid even if conversations are later set to private. The persist_chat_suggestions handler can be abused to inject attacker-controlled prompts, potentially influencing the AI model. There is no recycle bin or soft-delete, so deletions are permanent. The vulnerability is an IDOR (Insecure Direct Object Reference) affecting confidentiality, integrity, and availability.
Potential Impact
The vulnerability allows disclosure of full chat transcripts and retrieval histories containing sensitive document excerpts, violating confidentiality. Attackers can permanently delete any conversation, impacting availability. Integrity is compromised by renaming conversations and injecting attacker-controlled prompt suggestions, which may influence AI behavior. No elevated privileges are required; any authenticated user can exploit this. The exposure of UUIDs through public conversation listings facilitates exploitation. The lack of soft-delete means deleted conversations cannot be recovered. This is particularly impactful in enterprise environments where proprietary documents are indexed and queried.
Mitigation Recommendations
No official patch or fix is currently available as the vendor could not be reached for coordination. Users should monitor the vendor's GitHub repository and official website for future updates and patches. Until a fix is released, restrict authenticated user access to trusted parties only and consider additional access controls or network segmentation to limit exposure. Review and audit conversation UUID exposure in public listings to reduce risk. Avoid using Kotaemon in multi-user mode in sensitive environments until the issue is resolved.
Technical Details
- Classification
- {"confidence":0.63,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://kb.cert.org/vuls/id/754548","fetched":true,"fetchedAt":"2026-09-23T17:45:01.302Z","wordCount":753}
Threat ID: 6ab4101df7a7c541061cfecf
Added to database: 09/23/2026, 17:45:01 UTC
Last enriched: 09/23/2026, 17:45:07 UTC
Last updated: 09/24/2026, 04:12:48 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.