DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-86540: CVE-2026-86540: Arbitrary Code Execution via LSP Binary Override in knowns

CVE-2026-86540: Arbitrary Code Execution via LSP Binary Override in knowns

Vulnerability ID: CVE-2026-86540
CVSS Score: 8.5
Published: 2026-10-06

CVE-2026-86540 is a high-severity arbitrary code execution vulnerability in knowns, a repository management tool. The vulnerability occurs when the application parses and executes unvalidated language server binary overrides defined within a project's local configuration file.

TL;DR

Unvalidated binary paths in workspace configuration files allow arbitrary command execution when opening a repository in knowns.


Technical Details

  • CWE ID: CWE-78
  • Attack Vector: Local
  • CVSS v4.0 Base Score: 8.5
  • EPSS Score: 0.00212
  • Exploit Status: none/low
  • Impact: Arbitrary Code Execution (ACE)

Affected Systems

  • knowns
  • knowns: < 0.30.0 (Fixed in: 0.30.0)

Mitigation Strategies

  • Upgrade knowns to version 0.30.0 or higher.
  • Inspect workspace-level configuration files (.knowns/config.json) for unauthorized lsp binary overrides.
  • Restrict the opening of untrusted repositories in developer workspaces.

Remediation Steps:

  1. Download the latest package or build from source for version 0.30.0.
  2. Deploy static analysis or scanning tools to detect .knowns/config.json with binary configurations.
  3. Ensure any local binary configuration is whitelisted according to the new strict selection rules.

References


Read the full report for CVE-2026-86540 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)