CVE-2026-88939High· 8.3▾ MidnightPoC availableknowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project direct…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 45.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Exploit / PoC code exists
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88940Medium· 5.3knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
CVE-2026-86544High· 8.1knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations
CVE-2026-88899Critical· 9.8knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
CVE-2026-88938Medium· 6.5knowns through 0.33.0 Path Traversal via code.find MCP tool
CVE-2026-88937High· 8.8knowns through 0.33.0 Path Traversal via Template Engine
CVE-2026-86540High· 7.8knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file