CVE-2026-86544 knowns versions before 0.30.0 contain an authorization… — CVE Notify — TG.ME

🚨 CVE-2026-86544
knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.

🎖@cveNotify
GitHub
knowns/internal/permissions/guard.go at v0.29.1 · knowns-dev/knowns
The memory layer for AI-native development - giving AI persistent understanding of your software projects. - knowns-dev/knowns
September 7, 2026 44
CVE-2026-86544 knowns versions before 0.30.0 contain an authorization… — CVE Notify — TG.ME