Skip to content
Path Traversal Vulnerabilities in Knowns Affecting Multiple Versions

Path Traversal Vulnerabilities in Knowns Affecting Multiple Versions

First seen 11 Sep 2026, 00:45 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 03:16 UTC
  • Two path traversal vulnerabilities identified in Knowns software.
  • Affected versions include those before 0.30.0 and 0.33.0 and later.
  • No active exploitation confirmed, but immediate patching is recommended.

Two path traversal vulnerabilities have been identified in the Knowns software. The first vulnerability affects versions before 0.30.0, while the second affects versions 0.33.0 and later. Both vulnerabilities are categorized under CWE-22, which pertains to improper limitations of pathnames. Attackers can exploit these vulnerabilities via the Document API and Template Engine, potentially allowing unauthorized access to sensitive files. The vulnerabilities have been documented in GitHub Security Advisories (GHSA-3h35-4jq7-hv45 and GHSA-68cq-4rwm-f7jr). Users of affected versions are advised to prioritize patching to mitigate risks. No active exploitation has been confirmed as of now, but the vulnerabilities are significant enough to warrant immediate attention. The advisories provide guidance on vulnerability prioritization and early warning systems for ongoing threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-10
Advisory for Knowns before 0.30.0 published
Vulnerability GHSA-3h35-4jq7-hv45 disclosed affecting versions before 0.30.0.
www.vulncheck.com
2026-09-11
Advisory for Knowns through 0.33.0 published
Vulnerability GHSA-68cq-4rwm-f7jr disclosed affecting versions 0.33.0 and later.
www.vulncheck.com

More articles in this cluster (2)