An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although the contents are extracted into a temporary folder that is cleared before each extraction, successfully uploading a ZIP bomb could still cause the server to consume excessive resources during decompression. Moreover, if no further files are uploaded afterward, the extracted data could occupy disk space and potentially render the system unavailable. Anyone with permission to upload files can carry out this attack.
History

Mon, 24 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-409
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although the contents are extracted into a temporary folder that is cleared before each extraction, successfully uploading a ZIP bomb could still cause the server to consume excessive resources during decompression. Moreover, if no further files are uploaded afterward, the extracted data could occupy disk space and potentially render the system unavailable. Anyone with permission to upload files can carry out this attack.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-11-24T00:00:00.000Z

Updated: 2025-11-24T19:29:20.143Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63914

cve-icon Vulnrichment

Updated: 2025-11-24T19:28:39.186Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-24T20:15:50.320

Modified: 2025-11-25T22:16:16.690

Link: CVE-2025-63914

cve-icon Redhat

No data.