PT-2026-53164 · Khoj · Khoj
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
khoj-ai khoj versions prior to 2.0.0-beta.29
Description
A flaw in the Conversation Sharing Handler component within the file
src/khoj/routers/api chat.py allows for incorrect authorization. This occurs through the manipulation of the conversation.agent argument, enabling remote exploitation.Recommendations
Update to a version later than 2.0.0-beta.28.
As a temporary mitigation, restrict access to the Conversation Sharing Handler component.
Exploit
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Khoj