已知 0.31.0 之前的版本在 代理端点中未能正确验证 请求头。远程攻击者可以指定任意的目录路径,从而在主机系统的项目根目录之外执行文件操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knowns-dev | knowns | 0 ~ 0.31.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88937 | 8.8 HIGH | knowns through 0.33.0 Path Traversal via Template Engine |
| CVE-2026-88939 | 8.3 HIGH | knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption |
| CVE-2026-88938 | 6.5 MEDIUM | knowns through 0.33.0 Path Traversal via code.find MCP tool |
| CVE-2026-88940 | 5.3 MEDIUM | knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint |
No comments yet