Junglewise Threat Intelligence

CVE-2026-30633: knowns-dev knowns directory traversal in get_doc and update_doc tools

CVE-2026-30633 · Severity: info · CVSS 5.3 · Published 2026-07-21

Technologies: Knowns-Dev Knowns. Vendors: Knowns-Dev.

Executive brief

Knowns, a tool used for managing documentation via AI agents, contains a security flaw that allows unauthorized access to files. An attacker can use specially crafted file paths to read or modify Markdown (.md) files located outside of the designated documentation folder. This could lead to the exposure of sensitive internal notes or the unauthorized alteration of project documentation.

Technical details

A directory traversal vulnerability exists in the `resolveDocPath` function within `src/mcp/handlers/doc.ts`. The function fails to sanitize or validate `../` sequences in the `path` parameter before joining it with the base documentation directory. An attacker can exploit this via the Model Context Protocol (MCP) interface using the `get_doc` or `update_doc` tools. While the impact is limited to files with a `.md` extension (enforced by the code), an attacker can successfully read or overwrite any existing Markdown file on the host filesystem that the process has permissions to access. This can be triggered directly by an MCP client or indirectly through prompt injection against an AI agent integrated with the tool.

Affected products

  • knowns-dev knowns <= 0.11.4

Timeline

  • 2026-02-12: other: Vulnerability discovered and PoC created
  • 2026-07-21: disclosed: CVE-2026-30633 published

References

Related threats