Impact
Directory traversal in the get_doc and update_doc tools of knowns-dev/knowns 0.11.4 allows an attacker to read files outside the intended directory structure, potentially exposing sensitive information. This flaw is classified as CWE-22 and the description does not indicate that the attacker can create files or execute code.
Affected Systems
The vulnerability is reported for the knowns-dev/knowns software, specifically version 0.11.4. No other affected versions or extensions are listed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1 % suggests exploitation is uncommon at present and the vulnerability is not listed in CISA’s KEV catalog. The attack path relies on the get_doc and update_doc tools; the exact vector is not explicitly defined but is likely local or requires an attacker to have execution rights on a machine where these utilities are available.
OpenCVE Enrichment