External Control of File Operations in Known's Proxy Endpoint
CVE-2026-88899
9.3CRITICAL
What is CVE-2026-88899?
Versions of Known prior to 0.31.0 are susceptible to a vulnerability that allows remote attackers to manipulate the x-opencode-directory request header in the /api/opencode proxy endpoint. This flaw enables attackers to supply arbitrary directory paths, potentially executing unauthorized file operations beyond the designated project root on the host system. This raises significant security concerns, highlighting a critical need for updated validation measures in API handling.
Affected Version(s)
knowns 0 < 0.31.0
knowns 0.31.0
