Description
knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or achieve persistent code execution on victim systems.
Published: 2026-09-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

knowns through 0.33.0 fails to validate template destination paths traverse directories. This path traversal vulnerability lets attackers read or write arbitrary files outside the project root, which can be used to overwrite sensitive configuration files, exfiltrate credentials, or place executable payloads that enable persistent code execution. The weakness is classified as CWE‑22, and the CVSS score of 8.6 indicates a high severity impact on confidentiality, integrity, and availability.

Affected Systems

All installations of the open‑source knowns tool from the knowns‑dev org that use version 0.33.0 or earlier are affected. The vulnerability resides in the internal code‑generation template engine and is present in any build that includes that component before the patched release.

Risk and Exploitability

With a high CVSS score and no mitigation reported in the KEV catalog, the risk is significant for environments where the template generator is exposed. Attackers who can supply or influence template content can exploit the traversal flaw; exploitation does not require elevated privileges on the host filesystem if the tool runs under the same user as the victim processes. The EPSS score is not available, but the absence of a KEV listing does not reduce the threat level, especially for deployments that expose the template API to untrusted users.

Generated by OpenCVE AI on September 10, 2026 at 17:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade knowns to the latest patch release that includes proper path validation (e.g., version 0.34.0 or newer).
  • Restrict the template destination directories so that all writes are confined to the project root or a dedicated safe directory, and reject any paths containing directory traversal sequences.
  • Disable or tightly limit access to the template generation feature for unauthenticated or low‑privilege users, ensuring only trusted administrators can create or modify templates.

Generated by OpenCVE AI on September 10, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Knowns-dev
Knowns-dev knowns
Vendors & Products Knowns-dev
Knowns-dev knowns

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or achieve persistent code execution on victim systems.
Title knowns through 0.33.0 Path Traversal via Template Engine
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Knowns-dev Knowns
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T11:07:58.413Z

Reserved: 2026-09-10T14:55:19.856Z

Link: CVE-2026-88937

cve-icon Vulnrichment

Updated: 2026-09-10T16:03:10.312Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T16:18:12.273

Modified: 2026-09-10T19:58:20.507

Link: CVE-2026-88937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:45:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')