CVE-2026-86539: Knowns-Dev Knowns

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.

Affected products

Published 2026-09-07. Last modified 2026-09-09.