Description
knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve full file contents from outside the intended project directory.
Published: 2026-09-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote file read
Action: Immediate Patch
AI Analysis

Impact

The flaw occurs in knowns when the code.find MCP tool does not limit the path argument to the project root path or use relative traversal characters, causing the tool to open and return the contents of any file on the host system. The vulnerability is a classic directory traversal (CWE‑22) that can compromise the confidentiality of source code and other sensitive files, resulting in a full read of the host's file system accessible through the AI agent session.

Affected Systems

This issue exists in the knowns project from all releases up to and including 0.33.0. The affected vendor is knowns-dev, and the product is knowns. Users running any version earlier than 0.33.1 are susceptible.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high severity, while it is not listed in the CISA KEV catalog. The attack vector is inferred to be the code.find MCP tool accessed through an AI agent session, which may be reachable by any user with agent access. If an attacker can invoke this functionality, they can read arbitrary files on the host, exposing sensitive information and potentially facilitating further exploitation.

Generated by OpenCVE AI on September 10, 2026 at 18:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest knowns release (v0.33.1 or later) that constrains the path argument to the project root.
  • If a patch cannot be applied immediately, configure the system to disallow the code.find MCP tool from accessing files outside the project directory, for example by applying a custom path validation filter.
  • Restrict AI agent session privileges so that only authorized users can invoke the code.find MCP tool or disable the tool entirely for untrusted users.

Generated by OpenCVE AI on September 10, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Knowns-dev
Knowns-dev knowns
Vendors & Products Knowns-dev
Knowns-dev knowns

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve full file contents from outside the intended project directory.
Title knowns through 0.33.0 Path Traversal via code.find MCP tool
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Knowns-dev Knowns
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T19:20:52.053Z

Reserved: 2026-09-10T14:55:24.623Z

Link: CVE-2026-88938

cve-icon Vulnrichment

Updated: 2026-09-11T19:20:28.120Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T16:18:12.430

Modified: 2026-09-11T20:19:22.313

Link: CVE-2026-88938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:15:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')