Known Vulnerabilities for Knowns by Knowns-dev
Listed below are 10 of the newest known vulnerabilities associated with "Knowns" by "Knowns-dev".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-88940 json | knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88939 json | knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent s... | Not Provided | 2026-09-10 | 2026-09-15 |
| CVE-2026-88938 json | knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent ses... | Not Provided | 2026-09-10 | 2026-09-11 |
| CVE-2026-88937 json | knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88899 json | knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy en... | Not Provided | 2026-09-10 | 2026-09-11 |
| CVE-2026-86775 json | knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in inter... | Not Provided | 2026-09-09 | 2026-09-14 |
| CVE-2026-86544 json | knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly class... | Not Provided | 2026-09-07 | 2026-09-09 |
| CVE-2026-86543 json | knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no p... | Not Provided | 2026-09-07 | 2026-09-14 |
| CVE-2026-86542 json | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files o... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86541 json | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attacker... | Not Provided | 2026-09-07 | 2026-09-10 |