Server-Side Request Forgery in Known's Embedding Models API
CVE-2026-86539
6.9MEDIUM
What is CVE-2026-86539?
A server-side request forgery vulnerability exists in Known's API affecting all versions up to v0.33.0. The vulnerability is present in the POST /api/embedding-models/test endpoint, which allows attackers to send requests to arbitrary external destinations specified by the caller without proper validation. This could enable attackers to enumerate internal hosts and gain sensitive information about cloud metadata endpoints by exploiting the transport error messages that inadvertently disclose network reachability details. This breach of security could lead to further exploitation of internal resources.
Affected Version(s)
knowns 0 <= 0.33.0
