Description
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
Published: 2026-09-10
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in knowns versions older than 0.31.0, where the /api/opencode proxy fails to validate the x‑opencode‑directory HTTP header. An attacker can supply an arbitrary directory path in this header, and the server will use it when performing file operations outside the intended project root. This uncontrolled path traversal flaw (CWE‑73) can allow an attacker to read, modify, or delete arbitrary files, elevate privileges, or execute code on the host machine.

Affected Systems

This issue affects the open‑source data‑analysis tool knowns, maintained by knowns‑dev. Any installation running a release predating v0.31.0 is vulnerable, regardless of operating system or architecture.

Risk and Exploitability

The CVSS score of 9.3 indicates a severe impact. The EPSS score is not reported, but the lack of authentication requirements and the ability to supply the malicious header in a simple HTTP request mean the vulnerability can be exploited from a public reachable endpoint. The vulnerability is not yet listed in the CISA KEV catalog, but its high severity and broad applicability make it a high‑priority exposure.

Generated by OpenCVE AI on September 10, 2026 at 17:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade knowns to version 0.31.0 or later to apply the fix that validates the x‑opencode‑directory header.
  • If an upgrade cannot be performed immediately, filter or reject the x‑opencode‑directory header on the application or reverse‑proxy level, or disable the /api/opencode endpoint entirely.
  • Implement strict file‑system permissions or run the knowns agent under a restricted user account so that even if arbitrary paths are supplied, the host cannot be accessed beyond its intended scope.

Generated by OpenCVE AI on September 10, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Knowns-dev
Knowns-dev knowns
Vendors & Products Knowns-dev
Knowns-dev knowns

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
Title knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Knowns-dev Knowns
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T20:33:42.233Z

Reserved: 2026-09-10T11:28:50.297Z

Link: CVE-2026-88899

cve-icon Vulnrichment

Updated: 2026-09-11T17:11:18.203Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T16:18:12.120

Modified: 2026-09-11T21:17:55.460

Link: CVE-2026-88899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:15:17Z

Weaknesses
  • CWE-73

    External Control of File Name or Path