Vulnerability PYSEC-2026-1492
Medium Risk
MEDIUM RISK
CVSS Score: 5.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
July 07, 2026 at 02:34 PM UTC
Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
1.0
1.0
Summary
Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
Details
Summary
The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS.
Details
The q parameter for the /api/automation endpoint does not get correctly sanitized when rendered on the page, resulting in the ability of users to inject arbitrary HTML/JS.
PoC
POST /api/automation?q=%22%3E%3C%2Ftextarea%3E%3Cimg%20src%3Dx%20onerror%3Dalert(document.cookie)%3E%3Cscript%3Ealert(2)%3C%2Fscript%3E
Impact
Stored XSS: image
Fix
- Added a Content Security Policy to all config pages on the web client, including the automation page
- Used DOM scripting to construct all components on the config pages, including the automation page
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 days ago
khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem
2.0.0b23 - 2.0.0b25.dev10 GHSA-62mm-xwmv-crhg
2.0.0b23 - 2.0.0b25.dev10 GHSA-62mm-xwmv-crhg
Medium Risk
2 months ago
Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning
1.0 - 2.0.0b25.dev3 PYSEC-2026-1491
1.0 - 2.0.0b25.dev3 PYSEC-2026-1491
Medium Risk
2 months ago
khoj has an IDOR in subscription management allows unauthorized subscription modifications
1.0 - 1.28.4.dev94 PYSEC-2026-1493
1.0 - 1.28.4.dev94 PYSEC-2026-1493
Medium Risk
7 months ago
Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning
1.0 - 2.0.0b25.dev3 GHSA-6whj-7qmg-86qj
1.0 - 2.0.0b25.dev3 GHSA-6whj-7qmg-86qj
Medium Risk
1 year ago
khoj has an IDOR in subscription management allows unauthorized subscription modifications
1.0 - 1.28.4.dev94 GHSA-hq4h-w933-jm6c
1.0 - 1.28.4.dev94 GHSA-hq4h-w933-jm6c
Impacted packages
Timeline
Published
2 months ago
July 07, 2026 at 02:34 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:46 PM UTC