kotaemon <=0.12.0 Vulnerable to Remote Code Execution
The kotaemon package through version 0.12.0 appears to contain an insecure deserialization vulnerability that allows unauthenticated remote code execution. Users of kotaemon <=0.12.0 should assess their exposure.
What happened
An early warning has been issued regarding a critical vulnerability in the kotaemon package through version 0.12.0. The vulnerability, tracked as CVE-2026-69098, is an insecure deserialization issue in the check_connection endpoint. This vulnerability reportedly allows unauthenticated attackers to achieve remote code execution with application process privileges by supplying crafted YAML/JSON input with a __type__ field. The vulnerability is under investigation, and the CVSS score is 9.8, indicating a critical severity level.
To assess your exposure, check if your application or dependencies include kotaemon version 0.12.0 or earlier. If so, it is recommended to upgrade kotaemon to a version beyond 0.12.0 as soon as possible. Additionally, review any instances of the check_connection endpoint for potential exploitation. For the most accurate and up-to-date information, consult the primary sources, including the NVD page for CVE-2026-69098.
How 0Day mitigates this
kotaemon is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.