已知在 0.30.0 之前的版本中存在一个授权绕过漏洞,该漏洞表现为将修改型代码操作错误地分类为只读操作。拥有只读受限会话的攻击者可以利用 来修改权限配置,从而在后续调用中提升自身权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knowns-dev | knowns | 0 ~ 0.30.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86543 | 9.8 CRITICAL | knowns before 0.30.0 Unauthenticated Management API Exposure |
| CVE-2026-86542 | 9.1 CRITICAL | knowns before 0.30.0 Path Traversal via Import Name |
| CVE-2026-86439 | 8.8 HIGH | knowns before 0.30.0 Path Traversal via MCP doc and memory tools |
| CVE-2026-86541 | 8.3 HIGH | knowns before 0.30.0 Path Traversal via code.replace MCP action |
| CVE-2026-86540 | 7.8 HIGH | knowns before 0.30.0 Arbitrary Code Execution via LSP Binary |
| CVE-2026-86538 | 7.5 HIGH | knowns before 0.30.0 Path Traversal via templateFile parameter |
| CVE-2026-86539 | 7.2 HIGH | knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint |
No comments yet