Arbitrary Code Execution in Known's Project Configuration Files
CVE-2026-86540

8.5HIGH

Key Information:

Vendor

Knowns-dev

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86540?

An issue has been identified in Known's where versions prior to 0.30.0 do not validate the binary field in project configuration files. This vulnerability allows an attacker to craft a malicious .knowns/config.json file that, when a compromised repository is opened, executes the unvalidated binary path twice under the user's account. This execution happens without any verification, posing a significant security risk to users.

Affected Version(s)

knowns 0 < 0.30.0

knowns 0.30.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tong Hoang Gia
Nguyen Huy Hoang
.