PT-2025-47562 · Unknown · Cinnamon Kotaemon

Wang Yuanrong

·

Published

2025-11-20

·

Updated

2025-12-30

·

CVE-2025-63914

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cinnamon kotaemon version 0.11.0
Description The may extract zip function in the libsktemktemindexfileui.py file does not validate the contents of uploaded ZIP files. Uploading a ZIP bomb could lead to excessive resource consumption during decompression. Extracted data from a successful attack may occupy disk space, potentially causing system unavailability. Users with file upload permissions can exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-63914

Affected Products

Cinnamon Kotaemon