CVE-2025-63914

Source
https://cve.org/CVERecord?id=CVE-2025-63914
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63914.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-63914
Published
2025-11-24T00:00:00Z
Modified
2026-08-12T03:51:42Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although the contents are extracted into a temporary folder that is cleared before each extraction, successfully uploading a ZIP bomb could still cause the server to consume excessive resources during decompression. Moreover, if no further files are uploaded afterward, the extracted data could occupy disk space and potentially render the system unavailable. Anyone with permission to upload files can carry out this attack.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/63xxx/CVE-2025-63914.json"
}
References

Affected packages

Git / github.com/cinnamon/kotaemon

Affected ranges

Type
GIT
Repo
https://github.com/cinnamon/kotaemon
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:cinnamon:kotaemon:0.11.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.11.0"
        },
        {
            "last_affected": "0.11.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

0.*
0.11.0
v0.*
v0.11.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63914.json"