Path Traversal Vulnerability in Knowns MCP Tool by Knowns
CVE-2026-86439

8.7HIGH

Key Information:

Vendor

Knowns-dev

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86439?

The Knowns MCP tool prior to version 0.30.0 is susceptible to a path traversal vulnerability that occurs due to inadequate validation of filesystem paths in tool arguments. By exploiting this flaw, attackers may craft malicious path arguments containing directory traversal sequences, enabling them to read, create, overwrite, or delete files located outside of the project directory. This could potentially lead to the exposure of sensitive data or alter critical server files.

Affected Version(s)

knowns 0 < 0.30.0

knowns 0.30.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tong Hoang Gia
Nguyen Huy Hoang
.