← voltar
CVE-2024-43396

Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)

CVSS 5.4 MEDIUMEPSS 0.5%CWE-79
Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q parameter for the /api/automation endpoint does not get correctly sanitized when rendered on the page, resulting in the ability of users to inject arbitrary HTML/JS. This vulnerability is fixed in 1.15.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Produtos afetados
khoj-ai · khoj

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →