Path Traversal Vulnerability in Knowns Product by Known
CVE-2026-86538

8.7HIGH

Key Information:

Vendor

Knowns-dev

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86538?

The Knowns product prior to version 0.30.0 is susceptible to a path traversal vulnerability that affects the POST /api/templates/preview endpoint. This vulnerability allows unauthenticated attackers to manipulate the templateFile parameter. By using directory traversal sequences, attackers can bypass security restrictions and access sensitive files on the server, including configuration files and credentials. This poses a significant risk as it enables the unauthorized disclosure of potentially sensitive information through the JSON response returned by the API.

Affected Version(s)

knowns 0 < 0.30.0

knowns 0.30.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tong Hoang Gia
Nguyen Huy Hoang
.