CVE-2025-56526: XSS
Published Nov 18, 2025
·Updated
Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.
Affected Software
2 affected components
Kotaemon Kotaemon
Cinnamon kotaemon<=0.11.0
Remediation
Patch Available
Event History
Nov 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56526?
CVE-2025-56526 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-56526?
To fix CVE-2025-56526, update to the latest version of Kotaemon that has addressed this XSS vulnerability.
3
What impact does CVE-2025-56526 have on users?
CVE-2025-56526 allows attackers to execute arbitrary code, potentially leading to unauthorized access or data theft.
4
Is CVE-2025-56526 specific to certain versions of Kotaemon?
Yes, CVE-2025-56526 affects Kotaemon version 0.11.0 and may be present in earlier versions.
5
Can CVE-2025-56526 be exploited remotely?
Yes, CVE-2025-56526 can be exploited remotely by an attacker using a crafted PDF file.