
CVE-2025-57298 Disclosure.
Kotaemon is an open-source RAG (Retrieval-Augmented Generation) based document QA system that provides a web interface for querying uploaded documents such as PDF, Word, and Excel files.
A stored cross-site scripting (XSS) vulnerability exists in the document rendering pipeline of Kotaemon. User-controlled content is processed by an LLM and rendered in the web interface after markdown-to-HTML conversion without proper sanitization, allowing attacker-supplied HTML elements to be persistently injected into the page.
When a document is uploaded, the system automatically triggers a summarization request (e.g., "summary this file") as part of the normal processing flow. As a result, any uploaded document is implicitly passed through the markdown parsing and rendering pipeline, making the vulnerability exploitable via document upload alone without requiring explicit user interaction.
The following versions of Kotaemon are confirmed to be vulnerable:
kotaemon/blob/main/libs/ktem/ktem/utils/render.py
@staticmethod
def table(text: str) -> str:
"""Render table from markdown format into HTML"""
text = replace_mardown_header(text)
return markdown.markdown(
text,
extensions=[
"markdown.extensions.tables",
"markdown.extensions.fenced_code",
],
)
The application relies on the markdown.markdown() function to convert LLM-generated markdown content into HTML. However, the converted HTML output is rendered directly in the browser without HTML sanitization or output escaping.
As a result, markdown syntax that produces raw HTML elements—most notably the image syntax ![]()—is converted into executable HTML such as `` tags and stored in the conversation output.
"summary" means ""
The ability to inject persistent HTML elements allows attackers to:
/logout)Exploitation requires only a document upload and occurs automatically during summarization, with no additional user interaction.
Unsanitized HTML rendering may allow JavaScript execution via event handlers depending on the frontend rendering context.



This report was prepared by minnggyuu. (Team 404 Not Found, WhiteHat School 3rd Cohort, South Korea)
Email: [email protected]
GitHub: https://github.com/minnggyuu