CVE-2025-27518
Last modified
CVE-2025-27518 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend server allows arbitrary websites to send cross site requests to the application. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend server allows arbitrary websites to send cross site requests to the application. This vulnerability is fixed in commit 75079c3d3cf376381489b9a82ee46c69024e1a15.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-27518?
How severe is CVE-2025-27518?
How do I fix CVE-2025-27518?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27512Zincati is an auto-update agent for Fedora CoreOS hosts. Zin…2.1
- CVE-2025-27513OpenTelemetry dotnet is a dotnet telemetry framework. A vuln…7.5
- CVE-2025-27514GLPI is a Free Asset and IT Management Software package, Dat…5.4
- CVE-2025-27515Laravel is a web application framework. When using wildcard …9.8
- CVE-2025-27516Jinja is an extensible templating engine. Prior to 3.1.6, an…8.8
- CVE-2025-27517Volt is an elegantly crafted functional API for Livewire. Ma…9.3
- CVE-2025-27519Cognita is a RAG (Retrieval Augmented Generation) Framework …9.3
- CVE-2025-2752A vulnerability was found in Open Asset Import Library Assim…8.8
- CVE-2025-27520BentoML is a Python library for building online serving syst…9.8
- CVE-2025-27521Vulnerability of improper access permission in the process m…5.5
- CVE-2025-27522Deserialization of Untrusted Data vulnerability in Apache In…6.5
- CVE-2025-27523XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - S…8.7
Are you affected by CVE-2025-27518?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
