CVE-2026-13508

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation of the argument conversation.agent causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

28 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-28 22:16

Updated : 2026-06-28 22:16


NVD link : CVE-2026-13508

Mitre link : CVE-2026-13508

CVE.ORG link : CVE-2026-13508


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization

CWE-863

Incorrect Authorization