What is CVE-2026-30633?
A directory traversal vulnerability exists in knowns-dev/knowns version 0.11.4 via a crafted path value sent to the `get_doc` and `update_doc` tools. This allows an attacker to access arbitrary files on the server. Immediate update to the latest patched version is recommended.
Azərbaycanca: knowns-dev/knowns 0.11.4 versiyasında kataloq keçidi (directory traversal) zəifliyi aşkar edilib. Təcavüzkar `get_doc` və `update_doc` alətlərinə xüsusi hazırlanmış `path` dəyəri göndərərək serverdə ixtiyari fayllara giriş əldə edə bilər. Təcili olaraq `knowns` alətini ən son təhlükəsizlik yeniləməsinə qədər yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: knowns-dev
FAQ2
Which tools in knowns-dev/knowns are affected by CVE-2026-30633?
The vulnerability affects the `get_doc` and `update_doc` tools.
What can an attacker gain by exploiting this directory traversal vulnerability?
They can access arbitrary files on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.