CVE-2026-86542
published 2026-09-07CVE-2026-86542: knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory…
PriorityP263critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.74%
52.8th percentile
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| knowns-dev | knowns | < 0.30.0 | 0.30.0 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Knowns-dev Knowns up to 0.29.x Import Routes Name path traversal
vuldb·2026-09-08·CVSS 9.1
CVE-2026-86542 [CRITICAL] Knowns-dev Knowns up to 0.29.x Import Routes Name path traversal
A vulnerability was found in Knowns-dev Knowns up to 0.29.x. It has been classified as critical. The affected element is an unknown function of the component Import Routes. This manipulation of the argument Name causes path traversal.
This vulnerability is handled as CVE-2026-86542. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory.
ghsa_unreviewed·2026-09-08
CVE-2026-86542 [HIGH] CWE-22 knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory.
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/imports.go#L376-L420https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/imports.go#L519-L551https://github.com/knowns-dev/knowns/commit/d3989829fb5095666d23d005b2f78a082832a396https://github.com/knowns-dev/knowns/releases/tag/v0.30.0https://github.com/knowns-dev/knowns/security/advisories/GHSA-wh3c-v55g-qfg8https://www.vulncheck.com/advisories/knowns-before-0.30.0-path-traversal-via-import-name
2026-09-07
Published