Path Traversal Vulnerability in Knowns Before 0.30.0 by Known
CVE-2026-86542

8.8HIGH

Key Information:

Vendor

Knowns-dev

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86542?

The vulnerability in Knowns versions prior to 0.30.0 allows unauthenticated attackers to exploit the import routes by injecting traversal sequences into the name parameter. This can lead to unauthorized writing of files outside the designated imports directory, potentially overwriting sensitive files that are writable by the server process. A patch has been issued in version 0.30.0 to address this issue and secure against such attacks.

Affected Version(s)

knowns 0 < 0.30.0

knowns 0.30.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tong Hoang Gia
Nguyen Huy Hoang
.