knowns 在 0.30.0 之前的版本未能验证项目配置文件中 中的 字段,攻击者可以通过构造一个恶意的 文件来执行任意二进制程序。当打开包含该恶意配置的代码仓库时,未经校验的二进制路径会在用户账户下被执行两次,且没有任何校验机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knowns-dev | knowns | 0 ~ 0.30.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86543 | 9.8 CRITICAL | knowns before 0.30.0 Unauthenticated Management API Exposure |
| CVE-2026-86542 | 9.1 CRITICAL | knowns before 0.30.0 Path Traversal via Import Name |
| CVE-2026-86439 | 8.8 HIGH | knowns before 0.30.0 Path Traversal via MCP doc and memory tools |
| CVE-2026-86541 | 8.3 HIGH | knowns before 0.30.0 Path Traversal via code.replace MCP action |
| CVE-2026-86544 | 8.1 HIGH | knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions |
| CVE-2026-86538 | 7.5 HIGH | knowns before 0.30.0 Path Traversal via templateFile parameter |
| CVE-2026-86539 | 7.2 HIGH | knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint |
No comments yet