CVE-2025-27518 - CVE House
Back to Database
Status published Medium CVE-2025-27518

Cognita CORS misconfiguration in backend API server

Vulnerability Description

Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend server allows arbitrary websites to send cross site requests to the application. This vulnerability is fixed in commit 75079c3d3cf376381489b9a82ee46c69024e1a15.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27518

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

truefoundry

View all reports →

Affected Software

cognita
Vulnerable Versions:
< 75079c3d3cf376381489b9a82ee46c69024e1a15

Timeline

Official Publish: March 7th, 2025
Last Modified: March 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)