<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 18:58:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-267151</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267151</link>
      <description>EUVD-2026-267151</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267151</guid>
    </item>
    <item>
      <title>fkie_cve-2025-69207</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-69207</link>
      <description>&lt;p&gt;Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any user&amp;#39;s Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims&amp;#39; Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim&amp;#39;s Khoj search index. This attack requires knowing the user&amp;#39;s UUID which can be leaked through shared conversations where an AI generated image is present. This vulnerability is fixed in 2.0.0-beta.23.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any user&amp;#39;s Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims&amp;#39; Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim&amp;#39;s Khoj search index. This attack requires knowing the user&amp;#39;s UUID which can be leaked through shared conversations where an AI generated image is present. This vulnerability is fixed in 2.0.0-beta.23.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-69207</guid>
    </item>
    <item>
      <title>GHSA-6whj-7qmg-86qj — Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6whj-7qmg-86qj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: khoj&lt;/p&gt;
&lt;p&gt;### Summary
An IDOR in the Notion OAuth callback allows an attacker to hijack any user&amp;#39;s Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims&amp;#39; Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim&amp;#39;s Khoj search index.&lt;/p&gt;
&lt;p&gt;This attack requires knowing the user&amp;#39;s UUID which can be leaked through shared conversations where an AI generated image is present.&lt;/p&gt;
&lt;p&gt;### Details
When users share conversations which contain AI generated images, the file path for the image is constructed using the user&amp;#39;s UUID. Knowing this UUID, an attacker is able to intercept the OAuth callback for Notion and replace the `state` parameter with the other user&amp;#39;s UUID and sync notion onto their account.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The vulnerable line of code exists in `src/khoj/routers/notion.py` on the callback endpoint.
```python
@notion_router.get(&amp;#34;/auth/callback&amp;#34;)
async def notion_auth_callback(request: Request, background_tasks: BackgroundTasks):
    code = request.query_params.get(&amp;#34;code&amp;#34;)
    state = request.query_params.get(&amp;#34;state&amp;#34;)  # &amp;lt;-- Attacker controlled
    if not code or not state:
        return Response(&amp;#34;Missing code or state&amp;#34;, status_code=400)&lt;/p&gt;
&lt;p&gt;user: KhojUser = await aget_user_by_uuid(state)  # &amp;lt;-- No verification!&lt;/p&gt;
&lt;p&gt;await NotionConfig.objects.filter(user=user).adelete()  # &amp;lt;-- Deletes victim&amp;#39;s config
    
    #…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: khoj&lt;/p&gt;
&lt;p&gt;### Summary
An IDOR in the Notion OAuth callback allows an attacker to hijack any user&amp;#39;s Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims&amp;#39; Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim&amp;#39;s Khoj search index.&lt;/p&gt;
&lt;p&gt;This attack requires knowing the user&amp;#39;s UUID which can be leaked through shared conversations where an AI generated image is present.&lt;/p&gt;
&lt;p&gt;### Details
When users share conversations which contain AI generated images, the file path for the image is constructed using the user&amp;#39;s UUID. Knowing this UUID, an attacker is able to intercept the OAuth callback for Notion and replace the `state` parameter with the other user&amp;#39;s UUID and sync notion onto their account.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The vulnerable line of code exists in `src/khoj/routers/notion.py` on the callback endpoint.
```python
@notion_router.get(&amp;#34;/auth/callback&amp;#34;)
async def notion_auth_callback(request: Request, background_tasks: BackgroundTasks):
    code = request.query_params.get(&amp;#34;code&amp;#34;)
    state = request.query_params.get(&amp;#34;state&amp;#34;)  # &amp;lt;-- Attacker controlled
    if not code or not state:
        return Response(&amp;#34;Missing code or state&amp;#34;, status_code=400)&lt;/p&gt;
&lt;p&gt;user: KhojUser = await aget_user_by_uuid(state)  # &amp;lt;-- No verification!&lt;/p&gt;
&lt;p&gt;await NotionConfig.objects.filter(user=user).adelete()  # &amp;lt;-- Deletes victim&amp;#39;s config
    
    #…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6whj-7qmg-86qj</guid>
    </item>
    <item>
      <title>PYSEC-2026-1491 — Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1491</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: khoj&lt;/p&gt;
&lt;p&gt;### Summary
An IDOR in the Notion OAuth callback allows an attacker to hijack any user&amp;#39;s Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims&amp;#39; Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim&amp;#39;s Khoj search index.&lt;/p&gt;
&lt;p&gt;This attack requires knowing the user&amp;#39;s UUID which can be leaked through shared conversations where an AI generated image is present.&lt;/p&gt;
&lt;p&gt;### Details
When users share conversations which contain AI generated images, the file path for the image is constructed using the user&amp;#39;s UUID. Knowing this UUID, an attacker is able to intercept the OAuth callback for Notion and replace the `state` parameter with the other user&amp;#39;s UUID and sync notion onto their account.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The vulnerable line of code exists in `src/khoj/routers/notion.py` on the callback endpoint.
```python
@notion_router.get(&amp;#34;/auth/callback&amp;#34;)
async def notion_auth_callback(request: Request, background_tasks: BackgroundTasks):
    code = request.query_params.get(&amp;#34;code&amp;#34;)
    state = request.query_params.get(&amp;#34;state&amp;#34;)  # &amp;lt;-- Attacker controlled
    if not code or not state:
        return Response(&amp;#34;Missing code or state&amp;#34;, status_code=400)&lt;/p&gt;
&lt;p&gt;user: KhojUser = await aget_user_by_uuid(state)  # &amp;lt;-- No verification!&lt;/p&gt;
&lt;p&gt;await NotionConfig.objects.filter(user=user).adelete()  # &amp;lt;-- Deletes victim&amp;#39;s config
    
    #…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: khoj&lt;/p&gt;
&lt;p&gt;### Summary
An IDOR in the Notion OAuth callback allows an attacker to hijack any user&amp;#39;s Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims&amp;#39; Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim&amp;#39;s Khoj search index.&lt;/p&gt;
&lt;p&gt;This attack requires knowing the user&amp;#39;s UUID which can be leaked through shared conversations where an AI generated image is present.&lt;/p&gt;
&lt;p&gt;### Details
When users share conversations which contain AI generated images, the file path for the image is constructed using the user&amp;#39;s UUID. Knowing this UUID, an attacker is able to intercept the OAuth callback for Notion and replace the `state` parameter with the other user&amp;#39;s UUID and sync notion onto their account.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The vulnerable line of code exists in `src/khoj/routers/notion.py` on the callback endpoint.
```python
@notion_router.get(&amp;#34;/auth/callback&amp;#34;)
async def notion_auth_callback(request: Request, background_tasks: BackgroundTasks):
    code = request.query_params.get(&amp;#34;code&amp;#34;)
    state = request.query_params.get(&amp;#34;state&amp;#34;)  # &amp;lt;-- Attacker controlled
    if not code or not state:
        return Response(&amp;#34;Missing code or state&amp;#34;, status_code=400)&lt;/p&gt;
&lt;p&gt;user: KhojUser = await aget_user_by_uuid(state)  # &amp;lt;-- No verification!&lt;/p&gt;
&lt;p&gt;await NotionConfig.objects.filter(user=user).adelete()  # &amp;lt;-- Deletes victim&amp;#39;s config
    
    #…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1491</guid>
    </item>
  </channel>
</rss>
