CVE-2024-43396Medium· 5.4▾ SunlitKhoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 0.5%
The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS.
The q parameter for the /api/automation endpoint does not get correctly sanitized when rendered on the page, resulting in the ability of users to inject arbitrary HTML/JS.
POST /api/automation?q=%22%3E%3C%2Ftextarea%3E%3Cimg%20src%3Dx%20onerror%3Dalert(document.cookie)%3E%3Cscript%3Ealert(2)%3C%2Fscript%3E
Stored XSS:
khoj < 1.15.0Upgrade to a patched release:
khoj 1.15.0Connected by shared product, vendor, weakness, or advisory.