cbcvebase.

Knowns-Dev Knowns vulnerabilities

14 known vulnerabilities affecting knowns-dev/knowns.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH9MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-86538P1HIGHCVSS 7.5Exploitedfixed in 0.30.02026-09-07
CVE-2026-86538 [HIGH] CWE-22 CVE-2026-86538: knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/prev knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through t
nvd
CVE-2026-86543P2CRITICALCVSS 9.8fixed in 0.30.02026-09-07
CVE-2026-86543 [CRITICAL] CWE-306 CVE-2026-86543: knowns versions before 0.30.0 serve the management API without authentication on all network interfa knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
nvd
CVE-2026-88899P2CRITICALCVSS 9.8fixed in 0.31.02026-09-10
CVE-2026-88899 [CRITICAL] CWE-73 CVE-2026-88899: knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in t knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
nvd
CVE-2026-86542P2CRITICALCVSS 9.1fixed in 0.30.02026-09-07
CVE-2026-86542 [CRITICAL] CWE-22 CVE-2026-86542: knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated a knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.
nvd
CVE-2026-86775P2HIGHCVSS 8.6fixed in 0.30.02026-09-09
CVE-2026-86775 [HIGH] CWE-22 CVE-2026-86775: knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with cleanDocPath(), which strips leading/trailing slashes and the .md suffix but does not neutralize ../ traversal sequences, and internal/storage/doc_store.go
nvd
CVE-2026-86439P2HIGHCVSS 8.8fixed in 0.30.02026-09-07
CVE-2026-86439 [HIGH] CWE-22 CVE-2026-86439: knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing atta knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.
ghsanvd
CVE-2026-88937P3HIGHCVSS 8.8≤ 0.33.02026-09-10
CVE-2026-88937 [HIGH] CWE-22 CVE-2026-88937: knowns through 0.33.0 fails to properly validate template destination paths in the code generation t knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or achieve persistent code execution on vict
nvd
CVE-2026-86544P3HIGHCVSS 8.1fixed in 0.30.02026-09-07
CVE-2026-86544 [HIGH] CWE-863 CVE-2026-86544: knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code acti knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.
nvd
CVE-2026-88939P3HIGHCVSS 8.3≤ 0.33.02026-09-10
CVE-2026-88939 [HIGH] CWE-863 CVE-2026-88939: knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, a knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
nvd
CVE-2026-86541P3HIGHCVSS 8.3fixed in 0.30.02026-09-07
CVE-2026-86541 [HIGH] CWE-22 CVE-2026-86541: knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() func knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive files like shell startup scripts or S
nvd
CVE-2026-86540P3HIGHCVSS 7.8fixed in 0.30.02026-09-07
CVE-2026-86540 [HIGH] CWE-78 CVE-2026-86540: knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project co knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without
ghsanvd
CVE-2026-86539P3HIGHCVSS 7.2≤ 0.33.02026-09-07
CVE-2026-86539 [HIGH] CWE-918 CVE-2026-86539: knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embeddin knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability informati
nvd
CVE-2026-88938P3MEDIUMCVSS 6.5≤ 0.33.02026-09-10
CVE-2026-88938 [MEDIUM] CWE-22 CVE-2026-88938: knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project ro knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve full file contents from outside the intended project directory.
nvd
CVE-2026-88940P3MEDIUMCVSS 5.3≤ 0.33.02026-09-10
CVE-2026-88940 [MEDIUM] CWE-22 CVE-2026-88940: knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, a knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.
nvd
Knowns-Dev Knowns vulnerabilities | cvebase