---
id: CVE-2026-88940
title: >-
  knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse
  endpoint
summary: >-
  knowns through 0.33.0 fails to validate the path query parameter in the
  workspace browse endpoint, allowing remote attackers to enumerate arbitrary
  directories on the host filesystem. Attackers can traverse the directory
  structure to loc…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-22
vendor: knowns-dev
product: knowns
affected:
  - knowns <= 0.33.0
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T16:50:36.056383Z'
exploitAvailable: true
published: '2026-09-10'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T11:08:00.490Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-88940'
references:
  - url: >-
      https://github.com/knowns-dev/knowns/security/advisories/GHSA-h73x-698r-qrvg
    label: GitHub Security Advisory (GHSA-h73x-698r-qrvg)
  - url: >-
      https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/server/routes/workspace.go#L42-L110
  - url: >-
      https://www.vulncheck.com/advisories/knowns-through-0.33.0-arbitrary-directory-enumeration-via-workspace-browse-endpoint
    label: >-
      VulnCheck Advisory: knowns through 0.33.0 Arbitrary Directory Enumeration
      via workspace browse endpoint
tags:
  - cve.org
  - exploit-available
epss: 0.00464
epssPercentile: 0.3943
ingestedAt: '2026-09-11T16:45:47.922Z'
---

## Overview

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.

## Affected

- `knowns <= 0.33.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
