Path Traversal Vulnerability in Knowns MCP Tool by Knowns
CVE-2026-86439
8.7HIGH
What is CVE-2026-86439?
The Knowns MCP tool prior to version 0.30.0 is susceptible to a path traversal vulnerability that occurs due to inadequate validation of filesystem paths in tool arguments. By exploiting this flaw, attackers may craft malicious path arguments containing directory traversal sequences, enabling them to read, create, overwrite, or delete files located outside of the project directory. This could potentially lead to the exposure of sensitive data or alter critical server files.
Affected Version(s)
knowns 0 < 0.30.0
knowns 0.30.0
