Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-62mm-xwmv-crhg
  • PyPI/khoj
khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem 6 days ago
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-1491
  • PyPI/khoj
Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning 07 Jul
  • No fix available
  • Severity - 5.4 (Medium)
PYSEC-2026-1493
  • PyPI/khoj
khoj has an IDOR in subscription management allows unauthorized subscription modifications 07 Jul
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-1492
  • PyPI/khoj
Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature) 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-13508
  • github.com/khoj-ai/khoj
khoj-ai khoj Conversation Sharing api_chat.py authorization 28 Jun
  • No fix available
  • Severity - 2.0 (Low)
CVE-2025-69207
  • github.com/khoj-ai/khoj
Khoj has an IDOR in Notion OAuth Flow Enables Index Poisoning 02 Feb
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-6whj-7qmg-86qj
  • PyPI/khoj
Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning 02 Feb
  • No fix available
  • Severity - 5.4 (Medium)
CVE-2024-52294
  • github.com/khoj-ai/khoj
khoj has an IDOR in subscription management that allows unauthorized subscription modifications 30 Dec 2024
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-hq4h-w933-jm6c
  • PyPI/khoj
khoj has an IDOR in subscription management allows unauthorized subscription modifications 30 Dec 2024
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2024-43396
  • github.com/khoj-ai/khoj
Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature) 20 Aug 2024
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-cf72-vg59-4j4h
  • PyPI/khoj
Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature) 20 Aug 2024
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-564j-v29w-rqr6
  • PyPI/khoj-assistant
Khoj Open Redirect Vulnerability in Login Page 08 Jul 2024
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2024-25639
  • github.com/khoj-ai/khoj
Prompt Injection triggered XSS vulnerability in Khoj Obsidian, Desktop and Web clients 08 Jul 2024
  • Fix available
  • Severity - 5.9 (Medium)