Authorization Bypass in Known's Project Management Tool
CVE-2026-88939
8.7HIGH
What is CVE-2026-88939?
The Known project management tool version 0.33.0 is susceptible to an authorization bypass vulnerability due to the unguarded project.set action. This flaw enables users with read-only agent sessions to circumvent intended access restrictions, allowing them to redirect the server to a different project directory. As a result, attackers can acquire unintended write access capabilities, which poses significant security risks for users relying on the platform for project management.
Affected Version(s)
knowns 0 <= 0.33.0
