---
id: CVE-2026-86542
title: >-
  knowns before 0.30.0 fails to validate import names in the import routes,
  allowing unauthenticated attackers to write files outside the imports
  directory
summary: >-
  knowns before 0.30.0 fails to validate import names in the import routes,
  allowing unauthenticated attackers to write files outside the imports
  directory. Attackers can supply traversal sequences in the name parameter to
  escape the impor…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-22
vendor: knowns-dev
product: knowns
affected:
  - knowns < 0.30.0
published: '2026-09-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:56:50.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86542'
references:
  - url: >-
      https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/imports.go#L376-L420
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/imports.go#L519-L551
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/knowns-dev/knowns/commit/d3989829fb5095666d23d005b2f78a082832a396
    label: disclosure@vulncheck.com
  - url: 'https://github.com/knowns-dev/knowns/releases/tag/v0.30.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/knowns-dev/knowns/security/advisories/GHSA-wh3c-v55g-qfg8
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/knowns-before-0.30.0-path-traversal-via-import-name
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.0074
epssPercentile: 0.52734
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T12:43:09.777150Z'
ingestedAt: '2026-09-08T15:33:26.980Z'
---

## Overview

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
