CVE-2025-69207Disclosure(khoj / khoj)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any user's Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims' Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim's Khoj search index. This attack requires knowing the user's UUID which can be leaked through shared conversations where an AI generated image is present. This vulnerability is fixed in 2.0.0-beta.23.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • khoj

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-02); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
khoj

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-02: 1Mentions · 2026-02-03: 1Mentions · 2026-02-06: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-06: 102-0202-0302-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-021
Disclosure1
2026-02-031
General1
2026-02-061
Disclosure1
Full discourse3 posts
  • m0z@LooseSecurity
    Disclosure

    CVE-2025-69207 - This one was kind of funny. IDOR on Notion oauth flow could allow me to link my notion to any other account and subsequently poison agent indexes.

    Post summary

    The text discloses that CVE-2025-69207 is an IDOR vulnerability in Notion’s OAuth flow, enabling an attacker to link an account to another and poison agent indexes.

    000100837
    7.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-69207 Notion OAuth IDOR Vulnerability in Khoj AI App Before 2.0.0-beta.23 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69207

    Post summary

    A Notion OAuth IDOR vulnerability (CVE-2025-69207) affecting Khoj AI App versions before 2.0.0-beta.23 was disclosed, but the text provides no PoC, exploit, active exploitation, or patch details.

    0000083
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69207 Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any user's Notion integ… https://www.cve.org/CVERecord?id=CVE-2025-69207

    Post summary

    CVE-2025-69207 describes an IDOR flaw in Khoj's Notion OAuth callback (pre‑2.0.0-beta.23) that could allow hijacking of Notion integrations, but no PoC, exploit, patch, or active exploitation is reported.

    00000155
    56.5K followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
Appkhojkhoj---
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--
Appkhojkhoj2.0.0--

Explore more