Medium · 5.0 Node.js & npm GHSA-9gfj-28hw-jchp CVE-2026-86439
Knowns Path Traversal Flaw Allows Arbitrary File Read, Write, and Deletion via MCP Docs and Memory Tools
Knowns versions up to and including 0.29.1 contain multiple path traversal vulnerabilities in the MCP docs and memory tools, allowing attackers to read, write, or delete arbitrary files outside the intended project directory. A permission classification bug also allows deletion-restricted users to delete files via a rename operation. The issue is fixed in version 0.30.0.
AI summary
A security advisory (CVE-2026-86439 / GHSA-9gfj-28hw-jchp) describes multiple path traversal vulnerabilities in Knowns, a tool that exposes documentation and memory management functionality through MCP (Model Context Protocol) tools. The flaws affect the underlying storage layer used by both the 'docs' and 'memory' tools, as well as the permission system that governs which operations users are allowed to perform.
What happened
Knowns' internal storage functions for documents (doc_store.go) and memory entries (memory_store.go) build file paths by directly joining user-supplied input with a base directory, using Go's filepath.Join() function. Because this function resolves '../' sequences without any additional validation, an attacker can supply a path such as '../../../victim/secret' to make the server read, write, or delete files located outside the intended project directory. The MCP handlers for docs (doc.go) and memory (memory.go) pass user input straight through to these vulnerable storage functions without sanitizing it first.
Technical cause
The root cause is the absence of path containment checks after constructing file paths with filepath.Join(). None of the affected functions (Get, Create, Update, Rename, Delete in doc_store.go; GetInLayer, Create, Update, Delete in memory_store.go) verify that the resolved absolute path remains inside the intended base directory (e.g., via a strings.HasPrefix check), nor do they reject absolute paths or traversal sequences such as '..'. Separately, in the permission registry (registry.go), the 'docs.update' action is classified with the CapWrite capability even though, when called with a 'newPath' parameter, it triggers a Rename() operation that deletes the original file via os.Remove(). This capability misclassification (CWE-863) means a deletion is performed under a write-level permission check.
Why it matters
An attacker able to invoke the docs or memory MCP tools could read sensitive files outside the project, overwrite arbitrary files, or delete files on the host system — all through standard tool calls rather than requiring direct filesystem access. The advisory also notes that this vulnerability compounds a separately identified authentication bypass issue: when the Knowns server is started without a password, these MCP tools are reachable without any credentials, making exploitation possible without prior authentication in that configuration. The advisory does not state that the path traversal issue itself is unauthenticated by design; that additional risk applies specifically when the server is run without password protection.
Who is affected
Users running the 'knowns' package (npm ecosystem) in versions up to and including 0.29.1, specifically any deployment that exposes the docs or memory MCP tools, are affected.
Affected versions
All versions of knowns up to and including 0.29.1 are affected. The vulnerability is fixed in version 0.30.0.
Fixes and mitigation
The vendor has released version 0.30.0, which addresses the path traversal and capability misclassification issues described in the advisory. A patch is available via the project's GitHub releases page. The advisory does not provide further technical detail on the specific code changes beyond stating that a fix is available.
Recommended action
Upgrade knowns to version 0.30.0 or later as soon as possible. If immediate upgrading is not feasible, ensure the Knowns server is not run without password protection, since unauthenticated access significantly increases exploitability of this issue according to the advisory. Review any project documentation and memory directories for signs of files written or deleted outside the expected project scope.
PatchBriefing score
5.0 / 10 · Medium
Official CVSS: 8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Why this score
This issue carries a CVSS base score of 8.8 (High), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. The computed PatchBriefing score of 5 reflects the CVSS base score contribution (4.84) plus a small addition for the absence of required user interaction (0.2). There is no evidence of known exploitation in the wild or public exploit code, and no EPSS-driven score contribution was recorded in the provided data. A fix is available, which is factored into the deterministic scoring as not adding additional risk.
Affected versions
- knowns <= 0.29.1
- vulnerable
- ≥ 0.30.0
- patched
Reported fixes
The vendor has released version 0.30.0, which addresses the path traversal and capability misclassification issues described in the advisory. A patch is available via the project's GitHub releases page. The advisory does not provide further technical detail on the specific code changes beyond stating that a fix is available.
How this was built
1 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email