Server-Side Request Forgery in Known's Embedding Models API
CVE-2026-86539

6.9MEDIUM

Key Information:

Vendor

Knowns-dev

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86539?

A server-side request forgery vulnerability exists in Known's API affecting all versions up to v0.33.0. The vulnerability is present in the POST /api/embedding-models/test endpoint, which allows attackers to send requests to arbitrary external destinations specified by the caller without proper validation. This could enable attackers to enumerate internal hosts and gain sensitive information about cloud metadata endpoints by exploiting the transport error messages that inadvertently disclose network reachability details. This breach of security could lead to further exploitation of internal resources.

Affected Version(s)

knowns 0 <= 0.33.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tong Hoang Gia
Nguyen Huy Hoang
.