khoj-assistant@0.6.0 vulnerabilities

khoj-assistant is now khoj

Direct Vulnerabilities

Known vulnerabilities in the khoj-assistant package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Cross-site Scripting (XSS)

khoj-assistant is an An AI copilot for your Second Brain

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via prompt injection, due to accepting unsanitized input in the Obsidian, Desktop, and Web clients. An attacker who can convince a user to index a malicious page or read a page containing malicious instructions or prompts via the /online command can cause script execution on the user's system. This can effect undesired output from the user's application, exposure of sensitive information stored in the client, or interruption to the user's session.

How to fix Cross-site Scripting (XSS)?

Upgrade khoj-assistant to version 1.13.0 or higher.

[,1.13.0)
  • M
Open Redirect

khoj-assistant is an An AI copilot for your Second Brain

Affected versions of this package are vulnerable to Open Redirect through the next parameter on the login page. An attacker can redirect a victim to a malicious site by manipulating the URL parameter to point to an undesirable destination.

How to fix Open Redirect?

Upgrade khoj-assistant to version 1.14.0 or higher.

[,1.14.0)