PT-2024-21059 · Khoj · Khoj

Calligraf0

·

Published

2024-07-08

·

Updated

2024-08-28

·

CVE-2024-25639

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Khoj versions prior to 1.13.0
Description Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop, and Web clients inadequately sanitize the AI model's response and user inputs. This can trigger Cross Site Scripting (XSS) via Prompt Injection from untrusted documents either indexed by the user on Khoj or read by Khoj from the internet when the user invokes the "online" command.
Recommendations For versions prior to 1.13.0, update to version 1.13.0 to resolve the issue. As a temporary workaround, consider restricting the use of the /online command until the update is applied. Additionally, avoid using untrusted documents with the AI model to minimize the risk of exploitation.

Exploit

Fix

XSS

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-25639
GHSA-H2Q2-VCH3-72QM

Affected Products

Khoj