Impact
The vulnerability exists because knowns versions prior to 0.30.0 expose the management API on all network interfaces without requiring authentication. An unauthenticated attacker can invoke the /api/tunnel/start endpoint, which creates a public tunnel and republishes the API at an externally reachable address. This allows malicious actors to expose internal services to the internet without permission, potentially leading to further lateral movement or data disclosure.
Affected Systems
The affected product is knowns-dev:knowns, specifically all releases before 0.30.0. Installations of these versions that are reachable on the network are susceptible until an authenticated external access control is enforced or the software is updated.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but exposure on all interfaces makes the attack vector likely implicit network-based. Attackers with network reach to the host can exploit the unauthenticated endpoint without additional prerequisites, making the risk significant for any reachable deployment.
OpenCVE Enrichment