Knowns 0.33.0 版本在代码生成模板引擎中未能正确验证模板目标路径,使得攻击者能够读取和写入项目根目录之外的任意文件。攻击者可以构造恶意模板,通过目录遍历来覆盖 shell 配置文件、窃取凭证信息,或在受害系统上实现持久化的代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knowns-dev | knowns | 0 ~ 0.33.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88899 | 9.8 CRITICAL | knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory |
| CVE-2026-88939 | 8.3 HIGH | knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption |
| CVE-2026-88938 | 6.5 MEDIUM | knowns through 0.33.0 Path Traversal via code.find MCP tool |
| CVE-2026-88940 | 5.3 MEDIUM | knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint |
No comments yet