CVE-2026-86540: Arbitrary Code Execution via LSP Binary Override in knowns
Vulnerability ID: CVE-2026-86540
CVSS Score: 8.5
Published: 2026-10-06
CVE-2026-86540 is a high-severity arbitrary code execution vulnerability in knowns, a repository management tool. The vulnerability occurs when the application parses and executes unvalidated language server binary overrides defined within a project's local configuration file.
TL;DR
Unvalidated binary paths in workspace configuration files allow arbitrary command execution when opening a repository in knowns.
Technical Details
- CWE ID: CWE-78
- Attack Vector: Local
- CVSS v4.0 Base Score: 8.5
- EPSS Score: 0.00212
- Exploit Status: none/low
- Impact: Arbitrary Code Execution (ACE)
Affected Systems
- knowns
-
knowns: < 0.30.0 (Fixed in:
0.30.0)
Mitigation Strategies
- Upgrade knowns to version 0.30.0 or higher.
- Inspect workspace-level configuration files (.knowns/config.json) for unauthorized lsp binary overrides.
- Restrict the opening of untrusted repositories in developer workspaces.
Remediation Steps:
- Download the latest package or build from source for version 0.30.0.
- Deploy static analysis or scanning tools to detect .knowns/config.json with binary configurations.
- Ensure any local binary configuration is whitelisted according to the new strict selection rules.
References
Read the full report for CVE-2026-86540 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)