GHSA-564j-v29w-rqr6: Khoj Open Redirect Vulnerability in Login Page
An attacker can use the next
parameter on the login page to redirect a victim to a malicious page, while masking this using a legit-looking app.khoj.dev
url.
For example, https://app.khoj.dev/login?next=//example.com
will redirect to the https://example.com page.
References
Detect and mitigate GHSA-564j-v29w-rqr6 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →