CVE-2025-56527
Severity CVSS v4.0:
Pending analysis
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
18/11/2025
Last modified:
18/11/2025
Description
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/Cinnamon/kotaemon
- https://github.com/Cinnamon/kotaemon/commit/37cdc28
- https://github.com/HanTul/Kotaemon-CVE-2025-56526-56527-disclosure
- https://skinny-exoplanet-584.notion.site/Stored-XSS-via-Unsanitized-PDF-Content-Rendering-and-Plaintext-Credential-Exposure-in-LocalStorage-22cd1563bd3380458588eb49f361a363?pvs=74



