在版本 0.33.0 及之前, 操作被无条件地豁免于权限保护检查,这使得只读的 agent 会话能够绕过原有的访问限制。攻击者可以利用 将服务器指向另一个项目目录,从而获得写入权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knowns-dev | knowns | 0 ~ 0.33.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88899 | 9.8 CRITICAL | knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory |
| CVE-2026-88937 | 8.8 HIGH | knowns through 0.33.0 Path Traversal via Template Engine |
| CVE-2026-88938 | 6.5 MEDIUM | knowns through 0.33.0 Path Traversal via code.find MCP tool |
| CVE-2026-88940 | 5.3 MEDIUM | knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint |
No comments yet