Arbitrary Code Execution in Known's Project Configuration Files
CVE-2026-86540
8.5HIGH
What is CVE-2026-86540?
An issue has been identified in Known's where versions prior to 0.30.0 do not validate the binary field in project configuration files. This vulnerability allows an attacker to craft a malicious .knowns/config.json file that, when a compromised repository is opened, executes the unvalidated binary path twice under the user's account. This execution happens without any verification, posing a significant security risk to users.
Affected Version(s)
knowns 0 < 0.30.0
knowns 0.30.0
