CVE-2026-88899 | knowns-dev knowns up to 0.30.x Proxy Endpoint /api/opencode x-opencode-directory path traversal

SecurityVulns

A vulnerability classified as critical was found in knowns-dev knowns up to 0.30.x. The affected element is an unknown function of the file /api/opencode of the component Proxy Endpoint. Such manipulation of the argument x-opencode-directory leads to path traversal.

This vulnerability is uniquely identified as CVE-2026-88899. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More