CVE-2026-86775 | knowns-dev knowns up to 0.29.1 Document API docs.go cleanDocPath path path traversal

SecurityVulns

A vulnerability described as critical has been identified in knowns-dev knowns up to 0.29.1. Affected by this vulnerability is the function cleanDocPath of the file internal/server/routes/docs.go of the component Document API. The manipulation of the argument path results in path traversal.

This vulnerability is reported as CVE-2026-86775. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More