Impact
The flaw occurs in knowns when the code.find MCP tool does not limit the path argument to the project root path or use relative traversal characters, causing the tool to open and return the contents of any file on the host system. The vulnerability is a classic directory traversal (CWE‑22) that can compromise the confidentiality of source code and other sensitive files, resulting in a full read of the host's file system accessible through the AI agent session.
Affected Systems
This issue exists in the knowns project from all releases up to and including 0.33.0. The affected vendor is knowns-dev, and the product is knowns. Users running any version earlier than 0.33.1 are susceptible.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity, while it is not listed in the CISA KEV catalog. The attack vector is inferred to be the code.find MCP tool accessed through an AI agent session, which may be reachable by any user with agent access. If an attacker can invoke this functionality, they can read arbitrary files on the host, exposing sensitive information and potentially facilitating further exploitation.
OpenCVE Enrichment