Path Traversal Vulnerability in Knowns Tool by Knowns Dev
CVE-2026-88938

7.1HIGH

Key Information:

Vendor

Knowns-dev

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88938?

A vulnerability in the Knowns Tool versions prior to 0.33.0 allows attackers to exploit the path argument within the code.find MCP tool. This flaw fails to restrict file access to the intended project root directory, thereby enabling unauthorized retrieval of source files located elsewhere on the host system. Attackers can provide absolute paths or utilize relative path traversal techniques to access sensitive file contents beyond the designated project directory.

Affected Version(s)

knowns 0 <= 0.33.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tong Hoang Gia
.