CVE-2026-86540: Knowns-Dev Knowns
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.
Affected products
- Knowns-Dev Knowns: before 0.30.0 (fixed in 0.30.0)
Published 2026-09-07. Last modified 2026-09-08.