Knowns
Knowns: vulnerabilidades y CVE
Knowns tiene 10 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses10
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88940 | Media (6.9) | 0.56% | — | 10 sept 2026 | knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the… |
| CVE-2026-88939 | Alta (8.7) | 0.48% | — | 10 sept 2026 | knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at… |
| CVE-2026-88938 | Alta (7.1) | 0.48% | — | 10 sept 2026 | knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or… |
| CVE-2026-88937 | Alta (8.6) | 0.65% | — | 10 sept 2026 | knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply… |
| CVE-2026-86775 | Alta (8.8) | 0.75% | — | 9 sept 2026 | knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with cleanDocPath(),… |
| CVE-2026-86542 | Alta (8.8) | 0.74% | — | 7 sept 2026 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter… |
| CVE-2026-86541 | Alta (7.2) | 0.77% | — | 7 sept 2026 | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths… |
| CVE-2026-86540 | Alta (8.5) | 0.21% | — | 7 sept 2026 | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file.… |
| CVE-2026-86539 | Media (6.9) | 0.35% | — | 7 sept 2026 | knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can… |
| CVE-2026-86538 | Alta (8.7) | 0.98% | — | 7 sept 2026 | knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.