在 0.30.0 之前已知的版本中, 函数存在路径遍历漏洞,允许攻击者在项目根目录之外覆盖任意文件。攻击者可以通过提供绝对路径或包含目录遍历序列的相对路径,将恶意内容写入敏感文件,例如 Shell 启动脚本或 SSH 配置文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knowns-dev | knowns | 0 ~ 0.30.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86543 | 9.8 CRITICAL | knowns before 0.30.0 Unauthenticated Management API Exposure |
| CVE-2026-86542 | 9.1 CRITICAL | knowns before 0.30.0 Path Traversal via Import Name |
| CVE-2026-86439 | 8.8 HIGH | knowns before 0.30.0 Path Traversal via MCP doc and memory tools |
| CVE-2026-86544 | 8.1 HIGH | knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions |
| CVE-2026-86540 | 7.8 HIGH | knowns before 0.30.0 Arbitrary Code Execution via LSP Binary |
| CVE-2026-86538 | 7.5 HIGH | knowns before 0.30.0 Path Traversal via templateFile parameter |
| CVE-2026-86539 | 7.2 HIGH | knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint |
No comments yet