CVE-2025-53358 | Cinnamon kotaemon up to 0.10.6 ui.py index_fn path traversal (GHSA-jw4w-xcvf-jq5x / EUVD-2025-19740)
A vulnerability has been found in Cinnamon kotaemon up to 0.10.6 and classified as critical. This vulnerability affects the function index_fn of the file libs/ktem/ktem/index/file/ui.py. The manipulation leads to path traversal.
This vulnerability was named CVE-2025-53358. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.