CVE-2026-86540 knowns versions before 0.30.0 fail to validate the… — CVE Notify — TG.ME

🚨 CVE-2026-86540
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.

🎖@cveNotify
GitHub
knowns/internal/lsp/detect.go at v0.29.1 · knowns-dev/knowns
The memory layer for AI-native development - giving AI persistent understanding of your software projects. - knowns-dev/knowns
September 7, 2026 8