CVE-2026-88940
Dashboard / Vulnerabilities / CVE-2026-88940
CVE-2026-88940
Summary: knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
Details: knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88940.json, https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/server/routes/workspace.go#L42-L110, https://github.com/knowns-dev/knowns/security/advisories/GHSA-h73x-698r-qrvg, https://nvd.nist.gov/vuln/detail/CVE-2026-88940, https://www.vulncheck.com/advisories/knowns-through-0.33.0-arbitrary-directory-enumeration-via-workspace-browse-endpoint
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
