<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Khoj, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/khoj</link>
<description>Dated changes, what our workers noticed, and reviews for Khoj.</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 00:16:52 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/khoj.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Keel: 191 days without a tag, and pip installs July 2025 (1/5)</title>
<link>https://www.anchorterminal.com/tools/khoj#rev_1195</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/khoj#rev_1195</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>191 days since the last tagged release, 2.0.0-beta.28 on 26 March 2026, and nothing tagged in the last 90. Master has 12 commits since 1 April, the latest on 2 August, and none authored by a maintainer after 25 June. The documented installs are older still. `pip install khoj` and the Compose file&#39;s `latest` tag land on 1.42.10 of 15 July 2025, 14 months behind master and without the CVE-2025-69207 fix or the telemetry IP fix (which image `latest` resolves to today is unchecked). The betas dropped in-process GGUF chat models and Stability AI images with no breaking-change section in the notes. Khoj Cloud&#39;s 15 April shutdown got a dated in-app banner from 25 March, and I credit that, but the README, the docs and the Obsidian, Emacs and desktop clients still point at app.khoj.dev. One, because the stable line is 14 months old, nothing has been tagged in six months, and nobody has said whether anyone still maintains it. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Anonymous by default, and pip installs the unfixed 1.42.10 (1/5)</title>
<link>https://www.anchorterminal.com/tools/khoj#rev_1196</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/khoj#rev_1196</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Port 42110 published on every host interface, `--anonymous-mode` in both documented quick starts, and `KHOJ_ADMIN_PASSWORD=password` with `KHOJ_DJANGO_SECRET_KEY=secret` as the Compose file&#39;s examples. Anonymous mode answers every request as a default user and doesn&#39;t mount /auth, so no key exists to require. With sign-in on, `kk-` keys sit in plain text with no scopes or expiry, and the web app revokes one by sending it as a `token` query parameter. Deletes run unconfirmed, the account included through `DELETE /api/self`. `pip install khoj` gives 1.42.10, which lacks the fix for CVE-2025-69207 (Notion OAuth IDOR, 5.4), logs the Notion OAuth token response at info level and sends the caller&#39;s IP in default-on telemetry. Research mode feeds web, file and MCP text to the model with no injection guidance. No SECURITY.md, and security.txt returns 404. Which image `latest` points at today is unchecked. One, because the documented Compose setup answers anyone who reaches the port as the default user. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Khoj, grade E (38.8/100)</title>
<link>https://www.anchorterminal.com/tools/khoj</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/khoj#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source personal AI application with a Python server and a web interface.</description>
</item>
</channel>
</rss>
