{"id":"GHSA-6ph4-r249-58p2","title":"Duplicate Advisory: knowns vulnerable to command injection","summary":"Duplicate Advisory: knowns vulnerable to command injection","severity":"high","cvss":7.8,"cwe":["CWE-78"],"vendor":"knowns","product":"knowns","ecosystem":"npm","affected":["knowns < 0.30.0"],"patched":["knowns 0.30.0"],"published":"2026-09-08","updated":"2026-10-06","sourceUpdated":"2026-10-06T18:57:57Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-6ph4-r249-58p2","references":[{"url":"https://github.com/knowns-dev/knowns/security/advisories/GHSA-mc52-mwq4-vfx3"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86540"},{"url":"https://github.com/knowns-dev/knowns/commit/d3989829fb5095666d23d005b2f78a082832a396"},{"url":"https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/lsp/detect.go#L128-L157"},{"url":"https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/models/config.go#L205-L216"},{"url":"https://github.com/knowns-dev/knowns/releases/tag/v0.30.0"},{"url":"https://www.vulncheck.com/advisories/knowns-before-0.30.0-arbitrary-code-execution-via-lsp-binary"},{"url":"https://github.com/advisories/GHSA-6ph4-r249-58p2"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-06T19:13:33.846Z","slug":"GHSA-6ph4-r249-58p2","body":"## Overview\n\n# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-mc52-mwq4-vfx3. This link is maintained to preserve external references.\n\n# Original Description\n\nknowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.\n\n## Affected packages\n\n- `knowns < 0.30.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `knowns 0.30.0`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}