Safety vulnerability ID: 72980
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of Khoj contain a vulnerability in the Automation feature that allows users to inject arbitrary HTML or JavaScript, leading to Stored Cross-site Scripting (XSS) attacks. This issue occurs because the q parameter in the /api/automation endpoint was not properly sanitized when rendered on the page.
Latest version: 1.36.6
Your Second Brain
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application