<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T21:56:27.497856+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-267151</id>
    <title>EUVD-2026-267151</title>
    <updated>2026-10-08T21:56:27.500750+00:00</updated>
    <content>EUVD-2026-267151</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-267151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-69207</id>
    <title>fkie_cve-2025-69207</title>
    <updated>2026-10-08T21:56:27.500793+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any user's Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims' Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim's Khoj search index. This attack requires knowing the user's UUID which can be leaked through shared conversations where an AI generated image is present. This vulnerability is fixed in 2.0.0-beta.23.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-69207"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6whj-7qmg-86qj</id>
    <title>GHSA-6whj-7qmg-86qj — Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning</title>
    <updated>2026-10-08T21:56:27.500829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: khoj</p>
<p>### Summary
An IDOR in the Notion OAuth callback allows an attacker to hijack any user's Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims' Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim's Khoj search index.</p>
<p>This attack requires knowing the user's UUID which can be leaked through shared conversations where an AI generated image is present.</p>
<p>### Details
When users share conversations which contain AI generated images, the file path for the image is constructed using the user's UUID. Knowing this UUID, an attacker is able to intercept the OAuth callback for Notion and replace the `state` parameter with the other user's UUID and sync notion onto their account.</p>
<p>### PoC</p>
<p>The vulnerable line of code exists in `src/khoj/routers/notion.py` on the callback endpoint.
```python
@notion_router.get("/auth/callback")
async def notion_auth_callback(request: Request, background_tasks: BackgroundTasks):
    code = request.query_params.get("code")
    state = request.query_params.get("state")  # &lt;-- Attacker controlled
    if not code or not state:
        return Response("Missing code or state", status_code=400)</p>
<p>user: KhojUser = await aget_user_by_uuid(state)  # &lt;-- No verification!</p>
<p>await NotionConfig.objects.filter(user=user).adelete()  # &lt;-- Deletes victim's config
    
    #…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6whj-7qmg-86qj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1491</id>
    <title>PYSEC-2026-1491 — Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning</title>
    <updated>2026-10-08T21:56:27.500877+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: khoj</p>
<p>### Summary
An IDOR in the Notion OAuth callback allows an attacker to hijack any user's Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims' Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim's Khoj search index.</p>
<p>This attack requires knowing the user's UUID which can be leaked through shared conversations where an AI generated image is present.</p>
<p>### Details
When users share conversations which contain AI generated images, the file path for the image is constructed using the user's UUID. Knowing this UUID, an attacker is able to intercept the OAuth callback for Notion and replace the `state` parameter with the other user's UUID and sync notion onto their account.</p>
<p>### PoC</p>
<p>The vulnerable line of code exists in `src/khoj/routers/notion.py` on the callback endpoint.
```python
@notion_router.get("/auth/callback")
async def notion_auth_callback(request: Request, background_tasks: BackgroundTasks):
    code = request.query_params.get("code")
    state = request.query_params.get("state")  # &lt;-- Attacker controlled
    if not code or not state:
        return Response("Missing code or state", status_code=400)</p>
<p>user: KhojUser = await aget_user_by_uuid(state)  # &lt;-- No verification!</p>
<p>await NotionConfig.objects.filter(user=user).adelete()  # &lt;-- Deletes victim's config
    
    #…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1491"/>
  </entry>
</feed>
