CVE-2025-56527: High severity Kotaemon Kotaemon vulnerability
Published Nov 18, 2025
·Updated
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
Affected Software
2 affected components
Kotaemon Kotaemon
Cinnamon kotaemon<=0.11.0
Remediation
Patch Available
Event History
Nov 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56527?
CVE-2025-56527 has a medium severity rating due to the risks associated with plaintext password storage.
2
How do I fix CVE-2025-56527?
To fix CVE-2025-56527, implement secure password storage mechanisms such as hashing and avoid using localStorage for sensitive information.
3
Which versions of Kotaemon are affected by CVE-2025-56527?
CVE-2025-56527 affects Kotaemon versions up to and including 0.11.0.
4
What type of vulnerability is CVE-2025-56527?
CVE-2025-56527 is a security vulnerability related to plaintext password storage in localStorage.
5
Who is the vendor associated with CVE-2025-56527?
The vendor associated with CVE-2025-56527 is Cinnamon.