knowns-dev knowns

14 known vulnerabilities in knowns-dev knowns, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-88940 CVSS 6.9 medium knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate…
  • CVE-2026-88939 CVSS 8.7 high knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to…
  • CVE-2026-88938 CVSS 7.1 high knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read…
  • CVE-2026-88937 CVSS 8.6 high knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to…
  • CVE-2026-88899 CVSS 9.3 critical knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint…
  • CVE-2026-86775 CVSS 8.8 high knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in…
  • CVE-2026-86544 CVSS 7.2 high knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as…
  • CVE-2026-86543 CVSS 9.3 critical knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password…
  • CVE-2026-86542 CVSS 8.8 high knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the…
  • CVE-2026-86541 CVSS 7.2 high knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to…
  • CVE-2026-86540 CVSS 8.5 high knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers…
  • CVE-2026-86539 CVSS 6.9 medium knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues…
  • CVE-2026-86538 CVSS 8.7 high knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows…
  • CVE-2026-86439 CVSS 8.7 high knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and…