VYPR
High severity7.5NVD Advisory· Published Nov 18, 2025· Updated Jun 17, 2026

CVE-2025-56527

CVE-2025-56527

Description

Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Cinnamon/Kotaemon2 versions
    cpe:2.3:a:cinnamon:kotaemon:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cinnamon:kotaemon:*:*:*:*:*:*:*:*range: <=0.11.0
    • (no CPE)range: <0.11.0
  • Kotaemon/Kotaemondescription
  • HanTul/Kotaemonllm-create
    Range: <0.11.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.