A critical vulnerability tracked as CVE-2026-69098 affects Cinnamon's Kotaemon through version 0.12.0, allowing unauthenticated remote code execution through the Gradio-exposed /check_connection endpoint. The flaw arises because attacker-supplied YAML or JSON is deserialized with insecure settings, letting a request include a __type__ field that instantiates arbitrary Python classes on the server.
Public reporting says the issue can be exploited without credentials, API keys, or user interaction by abusing reachable event-handler endpoints such as /check_connection and /create_llm. Attackers can reportedly set __type__ to functions such as subprocess.check_output and pass arbitrary arguments to execute operating system commands with the application's privileges, creating risks of file access, database or code modification, and service disruption; the issue is classified as CWE-502 and has been rated critical, with one report assigning a CVSS 3.1 score of 10.0.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
The insecure deserialization vulnerability in Cinnamon's Kotaemon through version 0.12.0 was newly received as CVE-2026-69098. The CVE description states that crafted YAML or JSON input with a __type__ field can be abused to instantiate arbitrary Python classes and achieve unauthenticated remote code execution.
A GitHub issue disclosed a critical unauthenticated remote code execution flaw in Kotaemon 0.12.0, caused by publicly reachable Gradio endpoints and unsafe deserialization in the /check_connection endpoint. The write-up described how attackers could execute OS commands without credentials or user interaction.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.