knowns
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting knownspage 1 of 1
- CVE-2026-86439HIGHCVSS 8.8EG 8.8fixed in 0.30.02026-09-07
knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory t…
- CVE-2026-86540HIGHCVSS 7.8EG 7.8fixed in 0.30.02026-09-07
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository wit…
Check whether knowns is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for knowns CVEs against the assets you own.
Book a Demo →