Impact
This vulnerability exists in versions of the knowns npm package up to 0.29.1. The Document API normalizes input paths but fails to sanitize directory traversal sequences, allowing an attacker who can call the unprotected Management API to read, create, overwrite, or delete any markdown file on the host filesystem. By specifying paths such as …../../../../tmp/marker.md, an unauthenticated user can gain write access to arbitrary locations and potentially overwrite configuration or other critical files, raising the risk of a full compromise if code execution is later achieved through an additional vulnerability or misconfiguration. The flaw is fixed in version 0.30.0.
Affected Systems
The affected product is the open‑source knowns package from the knowns‑dev vendor. Versions 0.29.1 and earlier are released under the npm registry and are marked vulnerable when deployed in the default configuration, where the Management API is served on all interfaces without authentication.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity for remote, unauthenticated exploitation. The EPSS score is not available, but the lack of authentication and the easy construction of traversal payloads make the vulnerability likely to be exploited in practice. The vulnerability is not yet listed in CISA’s KEV catalog, yet it remains a significant risk for any publicly exposed deployment.
OpenCVE Enrichment