Impact
knowns through 0.33.0 fails to validate template destination paths traverse directories. This path traversal vulnerability lets attackers read or write arbitrary files outside the project root, which can be used to overwrite sensitive configuration files, exfiltrate credentials, or place executable payloads that enable persistent code execution. The weakness is classified as CWE‑22, and the CVSS score of 8.6 indicates a high severity impact on confidentiality, integrity, and availability.
Affected Systems
All installations of the open‑source knowns tool from the knowns‑dev org that use version 0.33.0 or earlier are affected. The vulnerability resides in the internal code‑generation template engine and is present in any build that includes that component before the patched release.
Risk and Exploitability
With a high CVSS score and no mitigation reported in the KEV catalog, the risk is significant for environments where the template generator is exposed. Attackers who can supply or influence template content can exploit the traversal flaw; exploitation does not require elevated privileges on the host filesystem if the tool runs under the same user as the victim processes. The EPSS score is not available, but the absence of a KEV listing does not reduce the threat level, especially for deployments that expose the template API to untrusted users.
OpenCVE Enrichment