Junglewise Threat Intelligence

CVE-2026-88940: Knowns path traversal in workspace browse endpoint

CVE-2026-88940 · Severity: medium · CVSS 5.3 · Published 2026-09-10

Technologies: Knowns-Dev Knowns. Vendors: Knowns-Dev.

Executive brief

Knowns is a workspace management system that allows users to organize and manage projects. A flaw in the directory browsing endpoint permits unauthenticated attackers to enumerate arbitrary directories on the host filesystem by manipulating the path query parameter, revealing the locations of all project directories and enabling reconnaissance for further attacks on project data.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in the workspace browse endpoint (GET /api/workspaces/browse, workspace.go:41-110). The browse() function accepts arbitrary ?path= query parameter values and passes them directly to os.ReadDir(filepath.Abs(dir)) without any allowlist validation or root-containment checks. An unauthenticated attacker can traverse the entire host filesystem and enumerate all valid Knowns project directories (identified by isProject: true markers), disclosing their absolute paths. This enumeration serves as the reconnaissance phase for a chained multi-stage exploit that combines it with a separate bootstrap gate bypass vulnerability (CWE-863) to escalate privileges and access arbitrary projects. No authentication or user interaction is required; the attack vector is network-accessible.

Affected products

  • knowns-dev knowns through 0.33.0

Timeline

  • 2026-09-10: disclosed: CVE-2026-88940 published on NVD

References

Related threats