Executive brief
knowns is an application that processes and previews template files. A vulnerability in the template preview endpoint allows unauthenticated attackers to read arbitrary files from the server by supplying directory traversal sequences, potentially exposing sensitive configuration data, credentials, and other confidential information.
Technical details
A path traversal vulnerability exists in the POST /api/templates/preview endpoint of knowns before version 0.30.0. The templateFile parameter is not properly validated, allowing attackers to supply sequences like "../" to traverse the filesystem and read files outside the intended template directory. The vulnerability is unauthenticated and requires only network access to the endpoint. Attackers can read arbitrary files on the server and receive the contents in the JSON response. The issue is fixed in version 0.30.0 and later, with a commit dated 2026-08-16 that implements filesystem path restrictions.
Affected products
- knowns knowns before 0.30.0
Timeline
- 2026-09-07: disclosed: CVE-2026-86538 published
- 2026-08-16: patched: Security fix committed to contain filesystem paths in version 0.30.0