CVE-2025-53358
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
02/07/2025
Last modified:
03/07/2025
Description
kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/index/file/ui.py, the index_fn method accepts both URLs and local file paths without validation. The pipeline streams these paths directly and stores them, enabling attackers to traverse directories (e.g. ../../../../../.env) and exfiltrate sensitive files. This issue has been patched via commit 37cdc28, in version 0.10.7 which has not been made public at time of publication.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM