Skip to content
Critical Path Traversal Vulnerability in knowns-dev Document API

Critical Path Traversal Vulnerability in knowns-dev Document API

First seen 14 Sep 2026, 15:18 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 16:52 UTC
  • CVE-2026-86775 allows unauthenticated file operations via path traversal.
  • Affected versions are knowns <= 0.29.1; fixed in version 0.30.0.
  • Immediate remediation is critical for self-hosted deployments with exposed APIs.

A path traversal vulnerability (CVE-2026-86775) has been identified in the knowns npm package versions <= 0.29.1, allowing unauthenticated attackers to perform arbitrary file operations on the host filesystem. The flaw arises from inadequate sanitization of user-supplied paths, enabling attackers to exploit the Document API by sending crafted requests to endpoints like POST /api/docs. This vulnerability can lead to unauthorized reading, creation, overwriting, or deletion of files with a .md extension, potentially exposing sensitive data or enabling further exploitation. The issue was published on 2026-09-09 and is fixed in version 0.30.0. Organizations using self-hosted deployments are particularly at risk, especially if the Management API is unauthenticated or exposed. Immediate action is recommended to mitigate potential impacts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-09
CVE-2026-86775 published
A path traversal vulnerability affecting knowns-dev was disclosed, allowing unauthorized file access.
Redpacketsecurity
2026-09-10
Vulnerability details reported
GitHub advisory outlines the exploitation method and impact of the path traversal vulnerability.
github.com
2026-09-10
Patch released
Version 0.30.0 of knowns was released to address the vulnerability, urging users to upgrade.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-86775 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed