Path Traversal Vulnerability in Knowns Document API by Knowns
CVE-2026-86775
8.8HIGH
What is CVE-2026-86775?
The Document API of Knowns versions prior to 0.30.0 features a path traversal vulnerability that allows remote, unauthenticated attackers to manipulate document paths. By exploiting this flaw, attackers can read, create, overwrite, or delete files with a .md extension anywhere on the host's filesystem, leading to potential exposure of sensitive data and corrupting other documentation. The affected code fails to properly sanitize user-supplied document paths, allowing for directory traversal attacks through crafted payloads. It is essential for users to upgrade to version 0.30.0 or later to mitigate this risk.
Affected Version(s)
knowns 0 < 0.30.0
knowns 0.30.0
