CVE-2026-69098 is an insecure deserialization vulnerability in Cinnamon kotaemon through version 0.12.0. The flaw is present in the check_connection endpoint, which accepts YAML or JSON input containing a type field and unsafely uses that field to instantiate Python classes. Because the endpoint does not adequately restrict or validate attacker-controlled type selection, an unauthenticated attacker can supply crafted input that causes arbitrary class instantiation. The described exploitation path abuses this behavior by setting type to subprocess.check_output and supplying attacker-controlled arguments, leading to arbitrary command execution on the host with the privileges of the application process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit for CVE-2026-69098 affecting kotaemon <= 0.12.0. It contains two files: a README describing the vulnerability and exploitation flow, and a single Python exploit script using only the standard library. The exploit targets an unauthenticated insecure deserialization flaw in kotaemon's Gradio-exposed LLM connection check. It first calls the create_llm handler to create a named LLM entry, then calls check_connection with a crafted YAML spec. That YAML abuses theflow deserialization with safe=False by specifying __type__ values that resolve to Python callables, ultimately invoking subprocess.check_output with attacker-controlled shell commands. The outer unittest.mock.Mock wrapper is used to absorb extra kwargs from the application while ensuring the nested subprocess call executes during recursive deserialization. The script supports two operational modes: direct command execution with returned stdout, and a detached bash reverse shell to an attacker-supplied HOST:PORT. Network interaction is entirely over HTTP to Gradio endpoints, with support for both /gradio_api/call/<api> and /call/<api> patterns and SSE-style result retrieval via event_id. Overall, this is a real, functional RCE exploit rather than a detector, and it is operational but not framework-integrated.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.