PT-2024-40091 · Khoj · Khoj

Published

2024-07-08

·

Updated

2024-07-08

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions: Khoj (affected versions not specified)
Description: The issue allows an attacker to redirect a victim to a malicious page by utilizing the next parameter on the login page, making it appear as a legitimate app.khoj.dev URL. For instance, the URL https://app.khoj.dev/login?next=//example.com will redirect to https://example.com. The problem seems to be related to a method in the auth.py file. This could potentially be used in phishing attempts, although the impact is considered low.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-564J-V29W-RQR6

Affected Products

Khoj