Executive brief
knowns is a document management and memory tool that processes file operations through MCP (Model Context Protocol) interfaces. Versions before 0.30.0 fail to properly validate file paths, allowing authenticated attackers to read, create, overwrite, and delete arbitrary Markdown files outside the intended project directory by supplying paths with directory traversal sequences (e.g., "../../../"). This could expose sensitive documents or allow an attacker to modify or remove critical files accessible to the server.
Technical details
The vulnerability is a path traversal (CWE-22) flaw in the MCP Docs and Memory Tools components of knowns. The vulnerable code in doc_store.go and memory_store.go fails to validate or sanitize filesystem paths passed as arguments to MCP tools, allowing directory traversal sequences to escape the intended project directory. The attack requires low-level privileges (authenticated access to the MCP interface) and network reachability, but no user interaction. An attacker can exploit this to read confidential Markdown files, overwrite files to alter data integrity, or delete files to impact availability. A fix was released in version 0.30.0.
Affected products
- knowns knowns before 0.30.0
Timeline
- 2026-09-08: disclosed: Advisory published to GitHub Advisory Database
- 2026-09-08: patched: Version 0.30.0 released with fix