Critical Unauthenticated Path Traversal Vulnerability in Khoj
A critical vulnerability (CVSS 8.7) exists in the Khoj application, allowing unauthenticated attackers to read arbitrary files from the server filesystem via the /home/ endpoint. This endpoint lacks path traversal filtering, path normalization checks, and authentication. Exploitation can lead to sensitive data exposure, including application configurations, system files, and potential facilitation of further attacks.