CVE-2024-43396
CVSS V2 None
CVSS V3 None
Description
Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q parameter for the /api/automation endpoint does not get correctly sanitized when rendered on the page, resulting in the ability of users to inject arbitrary HTML/JS. This vulnerability is fixed in 1.15.0.
Overview
- CVE ID
- CVE-2024-43396
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-08-20T20:23:05.660Z
- Last Modified Date
- 2024-08-20T20:23:05.660Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/khoj-ai/khoj/security/advisories/GHSA-cf72-vg59-4j4h | x_refsource_CONFIRM |
https://github.com/khoj-ai/khoj/commit/1c7a562880eeb7354325545d2cf6c5d1d1134812 | x_refsource_MISC |
https://github.com/khoj-ai/khoj/commit/55be90cdd2f9d6a09c8bf9ceea52fc36b9201626 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-43396 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-43396 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-08-21 13:20:13 | Added to TrackCVE |