High severity7.4NVD Advisory· Published Aug 28, 2026
CVE-2026-82281
CVE-2026-82281
Description
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.