Description
knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with cleanDocPath(), which strips leading/trailing slashes and the .md suffix but does not neutralize ../ traversal sequences, and internal/storage/doc_store.go then builds the target path with filepath.Join(ds.docsDir(), filepath.FromSlash(doc.Path)+".md") without verifying that the resolved path remains inside the documents directory. In the default deployment, where the Management API is unauthenticated and bound to all interfaces, a remote unauthenticated attacker can supply a traversal payload (for example {"path": "../../../../tmp/knowns_pwn_marker"} to POST /api/docs, or an encoded path to GET /api/docs/...) to read, create, overwrite, or delete arbitrary files with a .md extension anywhere on the host filesystem and to create arbitrary directories via os.MkdirAll. This can expose sensitive data stored in other projects' documentation, corrupt or destroy files, and provide an arbitrary-write primitive that may be chained toward code execution. The issue is fixed in version 0.30.0.
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read and Write via Path Traversal
Action: Immediate Patch
AI Analysis

Impact

This vulnerability exists in versions of the knowns npm package up to 0.29.1. The Document API normalizes input paths but fails to sanitize directory traversal sequences, allowing an attacker who can call the unprotected Management API to read, create, overwrite, or delete any markdown file on the host filesystem. By specifying paths such as …../../../../tmp/marker.md, an unauthenticated user can gain write access to arbitrary locations and potentially overwrite configuration or other critical files, raising the risk of a full compromise if code execution is later achieved through an additional vulnerability or misconfiguration. The flaw is fixed in version 0.30.0.

Affected Systems

The affected product is the open‑source knowns package from the knowns‑dev vendor. Versions 0.29.1 and earlier are released under the npm registry and are marked vulnerable when deployed in the default configuration, where the Management API is served on all interfaces without authentication.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity for remote, unauthenticated exploitation. The EPSS score is not available, but the lack of authentication and the easy construction of traversal payloads make the vulnerability likely to be exploited in practice. The vulnerability is not yet listed in CISA’s KEV catalog, yet it remains a significant risk for any publicly exposed deployment.

Generated by OpenCVE AI on September 9, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade knowns to version 0.30.0 or later where the path traversal logic has been corrected.
  • If an immediate upgrade is not feasible, restrict or disable the Management API by binding it only to localhost or by protecting the /api/docs endpoints with authentication and firewalls so that only trusted users can reach the vulnerable endpoints.
  • As a temporary measure, validate all file paths on the server side to ensure they are resolved inside the documents directory, or replace the vulnerable handlers with a minimal implementation that refuses any path containing '..' fragments.

Generated by OpenCVE AI on September 9, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Knowns-dev
Knowns-dev knowns
Vendors & Products Knowns-dev
Knowns-dev knowns

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with cleanDocPath(), which strips leading/trailing slashes and the .md suffix but does not neutralize ../ traversal sequences, and internal/storage/doc_store.go then builds the target path with filepath.Join(ds.docsDir(), filepath.FromSlash(doc.Path)+".md") without verifying that the resolved path remains inside the documents directory. In the default deployment, where the Management API is unauthenticated and bound to all interfaces, a remote unauthenticated attacker can supply a traversal payload (for example {"path": "../../../../tmp/knowns_pwn_marker"} to POST /api/docs, or an encoded path to GET /api/docs/...) to read, create, overwrite, or delete arbitrary files with a .md extension anywhere on the host filesystem and to create arbitrary directories via os.MkdirAll. This can expose sensitive data stored in other projects' documentation, corrupt or destroy files, and provide an arbitrary-write primitive that may be chained toward code execution. The issue is fixed in version 0.30.0.
Title knowns before 0.30.0 Path Traversal via Document API
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Knowns-dev Knowns
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T13:33:03.276Z

Reserved: 2026-09-08T11:35:02.617Z

Link: CVE-2026-86775

cve-icon Vulnrichment

Updated: 2026-09-14T13:32:56.639Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T14:17:28.533

Modified: 2026-09-14T14:17:17.037

Link: CVE-2026-86775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:15:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')