Open Redirect Affecting khoj-assistant package, versions [,1.14.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-KHOJASSISTANT-7430920
- published 9 Jul 2024
- disclosed 8 Jul 2024
- credit David Bors
How to fix?
Upgrade khoj-assistant
to version 1.14.0 or higher.
Overview
khoj-assistant is an An AI copilot for your Second Brain
Affected versions of this package are vulnerable to Open Redirect through the next
parameter on the login page. An attacker can redirect a victim to a malicious site by manipulating the URL parameter to point to an undesirable destination.