CVE Feed

    Dashboard / CVE / CVE-2024-43396

    CVE-2024-43396

    Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q parameter for the /api/automation endpoint does not get correctly sanitized when rendered on the page, resulting in the ability of users to inject arbitrary HTML/JS. This vulnerability is fixed in 1.15.0.

    Published:Aug 20, 2024
    Last Modified:Sep 3, 2024
    EPS:Aug 20, 2024
    EPSS Score:0.00085
    CVSS Score:5.4

    Affected Products

    Vendor
    Khoj
    Product
    Khoj

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High