VulnerabilityAnalyzed
CVE-2025-56527
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
HIGH 7.5EPSS 0.43%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-256
- Affected
- cinnamon/kotaemon
- Source
- cve@mitre.org
References
- https://github.com/Cinnamon/kotaemonProduct
- https://github.com/Cinnamon/kotaemon/commit/37cdc28Patch
- https://github.com/HanTul/Kotaemon-CVE-2025-56526-56527-disclosureExploit, Third Party Advisory
- https://harvest-sink-590.notion.site/Stored-XSS-via-Unsanitized-PDF-Content-Rendering-and-Plaintext-Credential-Exposure-in-LocalStorage-236770c3fe1e80f6a1aef381fb1c8f73Exploit, Third Party Advisory
- https://skinny-exoplanet-584.notion.site/Stored-XSS-via-Unsanitized-PDF-Content-Rendering-and-Plaintext-Credential-Exposure-in-LocalStorage-22cd1563bd3380458588eb49f361a363?pvs=74Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.