CVE-2025-27518

Source
https://cve.org/CVERecord?id=CVE-2025-27518
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27518.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-27518
Published
2025-03-07T15:36:48.366Z
Modified
2026-04-02T12:46:11.764217Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Cognita CORS misconfiguration in backend API server
Details

Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend server allows arbitrary websites to send cross site requests to the application. This vulnerability is fixed in commit 75079c3d3cf376381489b9a82ee46c69024e1a15.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27518.json"
}
References

Affected packages

Git / github.com/truefoundry/cognita

Affected ranges

Type
GIT
Repo
https://github.com/truefoundry/cognita
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27518.json"