在 0.30.0 之前的已知版本中,导入路由未对导入名称进行验证,使得未认证的攻击者能够向导入目录之外的位置写入文件。攻击者可以在 参数中提供路径遍历序列,从而跳出导入目录,覆盖服务器进程可写的任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knowns-dev | knowns | 0 ~ 0.30.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86543 | 9.8 CRITICAL | knowns before 0.30.0 Unauthenticated Management API Exposure |
| CVE-2026-86439 | 8.8 HIGH | knowns before 0.30.0 Path Traversal via MCP doc and memory tools |
| CVE-2026-86541 | 8.3 HIGH | knowns before 0.30.0 Path Traversal via code.replace MCP action |
| CVE-2026-86544 | 8.1 HIGH | knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions |
| CVE-2026-86540 | 7.8 HIGH | knowns before 0.30.0 Arbitrary Code Execution via LSP Binary |
| CVE-2026-86538 | 7.5 HIGH | knowns before 0.30.0 Path Traversal via templateFile parameter |
| CVE-2026-86539 | 7.2 HIGH | knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint |
No comments yet