CVE-2024-25639

MEDIUM

khoj < 1.13.0 - Cross-Site Scripting via AI Model Response and User Input

Title source: llm
STIX 2.1

Description

Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and user inputs. This can trigger Cross Site Scripting (XSS) via Prompt Injection from untrusted documents either indexed by the user on Khoj or read by Khoj from the internet when the user invokes the /online command. This vulnerability is fixed in 1.13.0.

Scores

CVSS v3 5.9
EPSS 0.0057
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-77 CWE-79 CWE-80
Status published
Products (1)
khoj/khoj < 1.13.0
Published Jul 08, 2024
Tracked Since Feb 18, 2026