Critical Path Traversal Vulnerability in knowns-dev Document API
Article Content
- •CVE-2026-86775 allows unauthenticated file operations via path traversal.
- •Affected versions are knowns <= 0.29.1; fixed in version 0.30.0.
- •Immediate remediation is critical for self-hosted deployments with exposed APIs.
A path traversal vulnerability (CVE-2026-86775) has been identified in the knowns npm package versions <= 0.29.1, allowing unauthenticated attackers to perform arbitrary file operations on the host filesystem. The flaw arises from inadequate sanitization of user-supplied paths, enabling attackers to exploit the Document API by sending crafted requests to endpoints like POST /api/docs. This vulnerability can lead to unauthorized reading, creation, overwriting, or deletion of files with a .md extension, potentially exposing sensitive data or enabling further exploitation. The issue was published on 2026-09-09 and is fixed in version 0.30.0. Organizations using self-hosted deployments are particularly at risk, especially if the Management API is unauthenticated or exposed. Immediate action is recommended to mitigate potential impacts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-86775 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…