1.21.1.dev5
2 years ago
6 months ago
Known vulnerabilities in the khoj-assistant package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
khoj-assistant is an An AI copilot for your Second Brain Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via prompt injection, due to accepting unsanitized input in the Obsidian, Desktop, and Web clients. An attacker who can convince a user to index a malicious page or read a page containing malicious instructions or prompts via the How to fix Cross-site Scripting (XSS)? Upgrade | [,1.13.0) |
khoj-assistant is an An AI copilot for your Second Brain Affected versions of this package are vulnerable to Open Redirect through the How to fix Open Redirect? Upgrade | [,1.14.0) |