Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2240982
AlmaLinux
5967
Alpaquita
16156
Alpine
4655
Android
3677
Azure Linux
17970
BellSoft Hardened Containers
770
Bitnami
9476
Chainguard
1048381
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68939
Echo
7865
GHC
3
GIT
109017
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148242
npm
229102
NuGet
1869
opam
29
openEuler
8900
openSUSE
14573
OSS-Fuzz
4018
Packagist
7101
Pub
11
PyPI
25463
Red Hat
23527
Rocky Linux
4342
Root
19625
RubyGems
5327
SUSE
23442
SwiftURL
60
TuxCare
9918
Ubuntu
65983
VSCode
21
Wolfi
293786
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-62mm-xwmv-crhg
PyPI/khoj
khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem
25 Sep
Fix available
Severity - 8.7 (High)
PYSEC-2026-1491
PyPI/khoj
Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning
07 Jul
No fix available
Severity - 5.4 (Medium)
PYSEC-2026-1493
PyPI/khoj
khoj has an IDOR in subscription management allows unauthorized subscription modifications
07 Jul
Fix available
Severity - 4.3 (Medium)
PYSEC-2026-1492
PyPI/khoj
Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
07 Jul
Fix available
Severity - 5.3 (Medium)
GHSA-6whj-7qmg-86qj
PyPI/khoj
Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning
02 Feb
No fix available
Severity - 5.4 (Medium)
GHSA-hq4h-w933-jm6c
PyPI/khoj
khoj has an IDOR in subscription management allows unauthorized subscription modifications
30 Dec 2024
Fix available
Severity - 4.3 (Medium)
GHSA-cf72-vg59-4j4h
PyPI/khoj
Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
20 Aug 2024
Fix available
Severity - 5.3 (Medium)
GHSA-564j-v29w-rqr6
PyPI/khoj-assistant
Khoj Open Redirect Vulnerability in Login Page
08 Jul 2024
Fix available
Severity - 6.3 (Medium)
PyPI - OSV