CVE-2026-88937
published 2026-09-10CVE-2026-88937: knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.65%
49.2th percentile
knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or achieve persistent code execution on victim systems.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| knowns-dev | knowns | <= 0.33.0 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/codegen/template_engine.go#L318-L344https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/codegen/template_engine.go#L625-L636https://github.com/knowns-dev/knowns/security/advisories/GHSA-68cq-4rwm-f7jrhttps://github.com/knowns-dev/knowns/security/advisories/GHSA-xjcg-5j3r-m6f9https://www.vulncheck.com/advisories/knowns-through-0.33.0-path-traversal-via-template-enginehttps://github.com/knowns-dev/knowns/security/advisories/GHSA-68cq-4rwm-f7jr
2026-09-10
Published