Junglewise Threat Intelligence

khoj unauthenticated path traversal in /home/ endpoint

Severity: medium · CVSS 4 · Published 2026-09-25

Technologies: khoj (PyPI). Vendors: PyPI.

Executive brief

Khoj is an open-source search and chat application. An unauthenticated attacker can read arbitrary files from the server's filesystem by exploiting a path traversal vulnerability in the /home/ endpoint, potentially exposing sensitive configuration, credentials, and system files without requiring any authentication or user interaction.

Technical details

The /home/{file_path:path} endpoint in web_client.py directly concatenates user-supplied input with a base directory without path normalization or traversal filtering, and lacks authentication decorators. An attacker can use ../ sequences to traverse outside the intended directory and read arbitrary files readable by the server process via network requests.

Affected products

  • khoj-ai khoj 2.0.0-beta.23 to 2.0.0-beta.25

Timeline

  • 2026-09-25: disclosed
  • 2026-09-25: patched: Fixed in 2.0.0-beta.25

References

Related threats