Browse all 8 CVE security advisories affecting knowns-dev. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-86544 | knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions — knowns CWE-863 | 8.1 | High | 2026-09-07 |
| CVE-2026-86543 | knowns before 0.30.0 Unauthenticated Management API Exposure — knowns CWE-306 | 9.8 | Critical | 2026-09-07 |
| CVE-2026-86542 | knowns before 0.30.0 Path Traversal via Import Name — knowns CWE-22 | 9.1 | Critical | 2026-09-07 |
| CVE-2026-86540 | knowns before 0.30.0 Arbitrary Code Execution via LSP Binary — knowns CWE-78 | 7.8 | High | 2026-09-07 |
| CVE-2026-86541 | knowns before 0.30.0 Path Traversal via code.replace MCP action — knowns CWE-22 | 8.3 | High | 2026-09-07 |
| CVE-2026-86539 | knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint — knowns CWE-918 | 7.2 | High | 2026-09-07 |
| CVE-2026-86538 | knowns before 0.30.0 Path Traversal via templateFile parameter — knowns CWE-22 | 7.5 | High | 2026-09-07 |
| CVE-2026-86439 | knowns before 0.30.0 Path Traversal via MCP doc and memory tools — knowns CWE-22 | 8.8 | High | 2026-09-07 |
This page lists every published CVE security advisory associated with knowns-dev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.