---
id: GHSA-6ph4-r249-58p2
title: 'Duplicate Advisory: knowns vulnerable to command injection'
summary: 'Duplicate Advisory: knowns vulnerable to command injection'
severity: high
cvss: 7.8
cwe:
  - CWE-78
vendor: knowns
product: knowns
ecosystem: npm
affected:
  - knowns < 0.30.0
patched:
  - knowns 0.30.0
published: '2026-09-08'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T18:57:57Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-6ph4-r249-58p2'
references:
  - url: >-
      https://github.com/knowns-dev/knowns/security/advisories/GHSA-mc52-mwq4-vfx3
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86540'
  - url: >-
      https://github.com/knowns-dev/knowns/commit/d3989829fb5095666d23d005b2f78a082832a396
  - url: >-
      https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/lsp/detect.go#L128-L157
  - url: >-
      https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/models/config.go#L205-L216
  - url: 'https://github.com/knowns-dev/knowns/releases/tag/v0.30.0'
  - url: >-
      https://www.vulncheck.com/advisories/knowns-before-0.30.0-arbitrary-code-execution-via-lsp-binary
  - url: 'https://github.com/advisories/GHSA-6ph4-r249-58p2'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-06T19:13:33.846Z'
---

## Overview

# Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-mc52-mwq4-vfx3. This link is maintained to preserve external references.

# Original Description

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.

## Affected packages

- `knowns < 0.30.0`

## Remediation

Upgrade to a patched release:

- `knowns 0.30.0`
