Khoj Obsidian Vulnerable to Cross Site Scripting (XSS) via Prompt Injection
CVE-2024-25639
7.5HIGH
What is CVE-2024-25639?
The Khoj application, known for creating personal AI agents, presents a vulnerability in its Obsidian, Desktop, and Web clients. This vulnerability arises from inadequate sanitization of user inputs and AI model responses, making systems susceptible to Cross Site Scripting (XSS) attacks. Specifically, an attacker could exploit this flaw through prompt injection by leveraging untrusted documents that the user has indexed or documents accessed via the /online command feature. This could lead to unauthorized script execution in the user's browser context. The vulnerability has been addressed in version 1.13.0 of the application.
Affected Version(s)
khoj < 1.13.0