Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Khoj
Khoj khoj |
|
| Vendors & Products |
Khoj
Khoj khoj |
Mon, 29 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 28 Jun 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation of the argument conversation.agent causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance. | |
| Title | khoj-ai khoj Conversation Sharing api_chat.py authorization | |
| First Time appeared |
Khoj-ai
Khoj-ai khoj |
|
| Weaknesses | CWE-285 CWE-863 |
|
| CPEs | cpe:2.3:a:khoj-ai:khoj:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Khoj-ai
Khoj-ai khoj |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-29T13:39:27.222Z
Reserved: 2026-06-28T06:21:13.647Z
Link: CVE-2026-13508
Updated: 2026-06-29T13:39:20.363Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T19:30:02Z