受影响版本 0.33.0 未能将 MCP 工具的 参数限制在项目根目录下,从而允许 AI 代理会话读取主机上任意位置的源文件。攻击者可以通过向 参数提供绝对路径或相对路径穿越序列,从而获取预期项目目录之外的完整文件内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knowns-dev | knowns | 0 ~ 0.33.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88899 | 9.8 CRITICAL | knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory |
| CVE-2026-88937 | 8.8 HIGH | knowns through 0.33.0 Path Traversal via Template Engine |
| CVE-2026-88939 | 8.3 HIGH | knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption |
| CVE-2026-88940 | 5.3 MEDIUM | knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint |
No comments yet