Path Traversal Vulnerability in Knowns Product by Known
CVE-2026-86538
8.7HIGH
What is CVE-2026-86538?
The Knowns product prior to version 0.30.0 is susceptible to a path traversal vulnerability that affects the POST /api/templates/preview endpoint. This vulnerability allows unauthenticated attackers to manipulate the templateFile parameter. By using directory traversal sequences, attackers can bypass security restrictions and access sensitive files on the server, including configuration files and credentials. This poses a significant risk as it enables the unauthorized disclosure of potentially sensitive information through the JSON response returned by the API.
Affected Version(s)
knowns 0 < 0.30.0
knowns 0.30.0
