Executive brief
knowns is a knowledge management system that uses MCP tools to manage Markdown files. Versions before 0.30.0 fail to validate file paths in tool arguments, allowing attackers to read, create, overwrite, and delete files anywhere on the system that the server process can access, not just within the intended project directory.
Technical details
The vulnerability is a directory traversal flaw in the MCP tool argument handling within knowns versions prior to 0.30.0. The vulnerable components (doc_store.go and memory_store.go) fail to properly validate and sanitize filesystem paths supplied as tool arguments, permitting attackers to inject path traversal sequences (e.g., "../") to access arbitrary files outside the project directory. An attacker can supply malicious path arguments to read, create, overwrite, or delete any Markdown file accessible to the server process with no authentication required. The fix is available in version 0.30.0 or later.
Affected products
- knowns-dev knowns before 0.30.0
Timeline
- 2026-09-07: disclosed