CVE-2026-88937
knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or achieve persistent code execution on victim systems.
- CVSS 4.0
- 8.6 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.52% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Source
- disclosure@vulncheck.com
References
- https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/codegen/template_engine.go#L318-L344
- https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/codegen/template_engine.go#L625-L636
- https://github.com/knowns-dev/knowns/security/advisories/GHSA-68cq-4rwm-f7jr
- https://github.com/knowns-dev/knowns/security/advisories/GHSA-xjcg-5j3r-m6f9
- https://www.vulncheck.com/advisories/knowns-through-0.33.0-path-traversal-via-template-engine
- https://github.com/knowns-dev/knowns/security/advisories/GHSA-68cq-4rwm-f7jr
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.