External Control of File Operations in Known's Proxy Endpoint
CVE-2026-88899

9.3CRITICAL

Key Information:

Vendor

Knowns-dev

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88899?

Versions of Known prior to 0.31.0 are susceptible to a vulnerability that allows remote attackers to manipulate the x-opencode-directory request header in the /api/opencode proxy endpoint. This flaw enables attackers to supply arbitrary directory paths, potentially executing unauthorized file operations beyond the designated project root on the host system. This raises significant security concerns, highlighting a critical need for updated validation measures in API handling.

Affected Version(s)

knowns 0 < 0.31.0

knowns 0.31.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tong Hoang Gia
.