Khoj is a focused search and retrieval platform with vulnerabilities centered on its core product and rooted in web application input handling and authorization logic. The recurring weakness classes—cross-site scripting, command injection, and authorization bypass—reflect common risks in user-facing search interfaces where input validation and access control are critical to security posture. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Khoj over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25639HIGH Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and user inputs. This can trigger C | Jul 8, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-69207HIGH Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any user's Notion integration by mani | Feb 2, 2026 | 7.1 | 21 | NO | NO |
CVE-2024-43396MEDIUM Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q | Aug 20, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Khoj.
Media articles that mention a CVE ID that affects a product developed by Khoj — matched by CVE ID, not by vendor name.