CVE-2026-86539: Knowns-Dev Knowns
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.
Affected products
- Knowns-Dev Knowns: up to and including 0.33.0
Published 2026-09-07. Last modified 2026-09-09.