CVE-2024-25639

MEDIUM

Khoj < 1.13.0 - Basic XSS

Title source: rule
STIX 2.1

Description

Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and user inputs. This can trigger Cross Site Scripting (XSS) via Prompt Injection from untrusted documents either indexed by the user on Khoj or read by Khoj from the internet when the user invokes the /online command. This vulnerability is fixed in 1.13.0.

Scores

CVSS v3 5.9
EPSS 0.0041
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79 CWE-77
Status published
Products (1)
khoj/khoj < 1.13.0
Published Jul 08, 2024
Tracked Since Feb 18, 2026