Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend server allows arbitrary websites to send cross site requests to the application. This vulnerability is fixed in commit 75079c3d3cf376381489b9a82ee46c69024e1a15.
History

Mon, 10 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
Description Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend server allows arbitrary websites to send cross site requests to the application. This vulnerability is fixed in commit 75079c3d3cf376381489b9a82ee46c69024e1a15.
Title Cognita CORS misconfiguration in backend API server
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-03-07T15:36:48.366Z

Updated: 2025-03-07T21:49:40.505Z

Reserved: 2025-02-26T18:11:52.307Z

Link: CVE-2025-27518

cve-icon Vulnrichment

Updated: 2025-03-07T21:49:36.198Z

cve-icon NVD

Status : Received

Published: 2025-03-07T16:15:39.187

Modified: 2025-03-07T16:15:39.187

Link: CVE-2025-27518

cve-icon Redhat

No data.