khoj-assistant@0.7.2.dev20 vulnerabilities

khoj-assistant is now khoj

  • latest version

    1.21.1.dev5

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    6 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the khoj-assistant package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Cross-site Scripting (XSS)

    khoj-assistant is an An AI copilot for your Second Brain

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via prompt injection, due to accepting unsanitized input in the Obsidian, Desktop, and Web clients. An attacker who can convince a user to index a malicious page or read a page containing malicious instructions or prompts via the /online command can cause script execution on the user's system. This can effect undesired output from the user's application, exposure of sensitive information stored in the client, or interruption to the user's session.

    How to fix Cross-site Scripting (XSS)?

    Upgrade khoj-assistant to version 1.13.0 or higher.

    [,1.13.0)
    • M
    Open Redirect

    khoj-assistant is an An AI copilot for your Second Brain

    Affected versions of this package are vulnerable to Open Redirect through the next parameter on the login page. An attacker can redirect a victim to a malicious site by manipulating the URL parameter to point to an undesirable destination.

    How to fix Open Redirect?

    Upgrade khoj-assistant to version 1.14.0 or higher.

    [,1.14.0)