Skip to content
RCE Vulnerability in Knowns LSP Configuration

RCE Vulnerability in Knowns LSP Configuration

First seen 7 Oct 2026, 19:36 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 21:34 UTC
  • •CVE-2026-86540 allows arbitrary code execution via insecure LSP configuration.
  • •Vulnerability affects any project using Knowns LSP with unvalidated binary paths.
  • •No active exploitation reported, but the vulnerability is critical with a CVSS of 8.5.

An Arbitrary Code Execution (ACE) vulnerability, CVE-2026-86540, has been identified in the Knowns Language Server Protocol (LSP) detection pipeline. The flaw arises from the system's failure to validate the.binary field in the.knowns/config.json file, allowing execution of attacker-controlled binaries. This vulnerability can be exploited by opening a malicious or compromised repository, leading to immediate execution of malicious code. The payload is executed twice per session, enabling a fully unauthenticated Remote Code Execution chain when combined with existing Config Overwrite vulnerabilities. The vulnerability is categorized as due to its potential for, with a CVSS score of 8.5. As of now, there are no reports of in the wild, but the flaw remains. Security professionals are advised to review their configurations and apply necessary mitigations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-07
CVE-2026-86540 published
The vulnerability was disclosed with a CVSS score of 8.5, highlighting its critical nature.
Advisories.Gitlab

More articles in this cluster (3)

Following this threat?

Track CVE-2026-86540 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected?
Any project using Knowns LSP that relies on the .knowns/config.json configuration file.
Is there a patch available?
Currently, there is no patch available for CVE-2026-86540.
How can I mitigate this vulnerability?
Review and validate the .binary field in your .knowns/config.json to prevent execution of untrusted binaries.