Path Traversal Vulnerability in Known's handleCodeReplace Function
CVE-2026-86541

7.2HIGH

Key Information:

Vendor

Knowns-dev

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86541?

The Known product prior to version 0.30.0 contains a path traversal vulnerability in the handleCodeReplace() function. This security flaw permits attackers to manipulate the file system by supplying absolute or relative paths that exploit directory traversal sequences. As a result, they may overwrite files located outside the project root, potentially compromising sensitive files, such as shell startup scripts or SSH configuration files. This situation exposes users to significant risks, ensuring that immediate updates to secure versions are crucial.

Affected Version(s)

knowns 0 < 0.30.0

knowns 0.30.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tong Hoang Gia
Nguyen Huy Hoang
.