CVE-2025-56527

Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
Configurations

No configuration.

History

19 Nov 2025, 15:15

Type Values Removed Values Added
References
  • () https://harvest-sink-590.notion.site/Stored-XSS-via-Unsanitized-PDF-Content-Rendering-and-Plaintext-Credential-Exposure-in-LocalStorage-236770c3fe1e80f6a1aef381fb1c8f73 -

18 Nov 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 17:16

Updated : 2025-11-19 19:14


NVD link : CVE-2025-56527

Mitre link : CVE-2025-56527

CVE.ORG link : CVE-2025-56527


JSON object : View

Products Affected

No product.

CWE
CWE-256

Plaintext Storage of a Password