PT-2024-21059 · Khoj · Khoj
Calligraf0
·
Published
2024-07-08
·
Updated
2024-08-28
·
CVE-2024-25639
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Khoj versions prior to 1.13.0
Description
Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop, and Web clients inadequately sanitize the AI model's response and user inputs. This can trigger Cross Site Scripting (XSS) via Prompt Injection from untrusted documents either indexed by the user on Khoj or read by Khoj from the internet when the user invokes the "online" command.
Recommendations
For versions prior to 1.13.0, update to version 1.13.0 to resolve the issue. As a temporary workaround, consider restricting the use of the /online command until the update is applied. Additionally, avoid using untrusted documents with the AI model to minimize the risk of exploitation.
Exploit
Fix
XSS
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Khoj