CVE-2026-86775
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Knowns NPM Package

Vulnerability report for CVE-2026-86775, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with cleanDocPath(), which strips leading/trailing slashes and the .md suffix but does not neutralize ../ traversal sequences, and internal/storage/doc_store.go then builds the target path with filepath.Join(ds.docsDir(), filepath.FromSlash(doc.Path)+".md") without verifying that the resolved path remains inside the documents directory. In the default deployment, where the Management API is unauthenticated and bound to all interfaces, a remote unauthenticated attacker can supply a traversal payload (for example {"path": "../../../../tmp/knowns_pwn_marker"} to POST /api/docs, or an encoded path to GET /api/docs/...) to read, create, overwrite, or delete arbitrary files with a .md extension anywhere on the host filesystem and to create arbitrary directories via os.MkdirAll. This can expose sensitive data stored in other projects' documentation, corrupt or destroy files, and provide an arbitrary-write primitive that may be chained toward code execution. The issue is fixed in version 0.30.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
knowns-dev knowns to 0.30.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86775 is a path traversal vulnerability in the knowns npm package versions 0.29.1 and below. It allows unauthenticated attackers to manipulate file paths by exploiting improper path sanitization in the Document API. The flaw enables reading, writing, deleting, or creating files with a .md extension outside the intended directory, including sensitive system files. The issue stems from unsafe path construction in docs.go and doc_store.go where traversal sequences like ../ are not neutralized.

Detection Guidance

Check if the knowns package version is <= 0.29.1 by running: npm list knowns. If vulnerable, inspect network traffic for POST requests to /api/docs with paths containing ../ or encoded traversal sequences. Review filesystem for unexpected .md files outside the intended directory.

Impact Analysis

This vulnerability can expose sensitive data stored in other projects' documentation, corrupt or destroy critical files, and provide a way to plant malicious payloads. Attackers can create arbitrary directories and perform unauthorized file operations anywhere on the host filesystem. In default deployments with an unauthenticated Management API, remote attackers can exploit this without authentication to gain arbitrary write access, potentially leading to code execution.

Compliance Impact

This vulnerability can lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's confidentiality requirements. Exposure of personal or health information due to file traversal could result in regulatory fines, legal liabilities, and loss of compliance certifications. The ability to modify or delete files may also breach integrity and availability requirements under these standards.

Mitigation Strategies

Upgrade the knowns package to version 0.30.0 or later using: npm update knowns. If immediate upgrade is not possible, restrict access to the Management API by binding it to localhost only and enabling authentication. Monitor for suspicious file operations in the filesystem.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86775. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart