CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-86540

CVE-2026-86540: Arbitrary Code Execution via LSP Binary Override in knowns

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 6, 2026·5 min read·5 visits

Executive Summary (TL;DR)

Unvalidated binary paths in workspace configuration files allow arbitrary command execution when opening a repository in knowns.

CVE-2026-86540 is a high-severity arbitrary code execution vulnerability in knowns, a repository management tool. The vulnerability occurs when the application parses and executes unvalidated language server binary overrides defined within a project's local configuration file.

Vulnerability Overview

The vulnerability CVE-2026-86540 describes an arbitrary code execution vulnerability in knowns, a developer tool and repository management application. The issue is located within the workspace configuration processing component, which handles project-level settings when a workspace directory is opened.\n\nIn vulnerable versions of the application, opening a directory containing a crafted .knowns/config.json configuration file allows the application to automatically parse and load settings without verification. The vulnerability is triggered during workspace startup, when the application attempts to initialize the Language Server Protocol (LSP) environment using paths specified in the configuration file.\n\nBecause the workspace initialization occurs automatically upon opening the directory, the application requires minimal user interaction to trigger the vulnerability beyond opening the workspace. This behavior exposes a significant attack surface to untrusted repositories, such as open-source projects or shared codebases.

Root Cause Analysis

The root cause of CVE-2026-86540 is a failure to sanitize and validate input in the settings.lsp.languages.<lang>.binary configuration property, which is mapped to the CWE-78 weakness class (Improper Neutralization of Special Elements used in an OS Command).\n\nWhen knowns initializes, the internal/lsp/detect.go component resolves the configured binary path via Detector.resolve. The resolution logic reads the user-supplied string from the local project configuration and instantiates a Binary object directly using this parameter without validation.\n\nBecause there is no verification that the user-supplied string matches a safe or pre-registered executable binary name, the application passes this unvalidated string to execution subshells. The execution is performed twice during the application workflow: first during workspace detection routines using functions like exec.LookPath, and second when starting the language server daemon via StartLanguage in internal/lsp/manager.go. Consequently, any system command or path to a local executable specified in the configuration file is executed with the privileges of the running application process.

Technical Diagram & Flow

The following diagram illustrates the technical execution flow from loading the malicious configuration to process execution under the user's privilege context.\n\nmermaid\ngraph LR\n A["Malicious Directory Opened"] --> B["Parse .knowns/config.json"]\n B --> C["Extract settings.lsp.languages.go.binary"]\n C --> D["Instantiate Binary with raw string"]\n D --> E["Detector.resolve checks binary"]\n E --> F["System executes payload via exec.LookPath / StartLanguage"]\n

Source Code Analysis

The vulnerability exists in the way internal/lsp/detect.go resolves overrides. In vulnerable versions, the application takes the raw string directly from the config file and creates a Binary structure.\n\nBelow is the vulnerable code block from version 0.29.1:\n\ngo\n// Vulnerable Code in internal/lsp/detect.go\nfunc (d *Detector) resolve(ctx context.Context, root string, lang Language, override string) (ServerCommand, bool) {\n\tbinaries := lang.Binaries\n\tif override != "" {\n\t\tbinary := Binary{Name: override} // Raw, unvalidated override string is accepted\n\t\tif len(binaries) > 0 {\n\t\t\tbinary.CheckArgs = append([]string(nil), binaries[0].CheckArgs...)\n\t\t}\n\t\tbinaries = []Binary{binary}\n\t}\n\t// ...\n}\n\n\nThe official patch in version 0.30.0 addresses this by introducing strict whitelist verification functions within internal/lsp/binary_override.go. The validation functions verify that the override string is an exact match for one of the pre-registered binaries associated with the corresponding language adapter.\n\nBelow is the patched implementation of the verification and resolution routines:\n\ngo\n// Patched Code in internal/lsp/binary_override.go\nfunc selectBinaryOverride(override string, candidates []Binary) (Binary, error) {\n\tif strings.TrimSpace(override) != override || override == "" {\n\t\treturn Binary{}, invalidBinaryOverride(override)\n\t}\n\tfor _, candidate := range candidates {\n\t\tif candidate.Name == override {\n\t\t return candidate, nil // Returns the binary only if it matches a registered candidate\n\t\t}\n\t}\n\treturn Binary{}, invalidBinaryOverride(override)\n}\n\n// Patched Code in internal/lsp/detect.go\nfunc (d *Detector) resolve(ctx context.Context, root string, lang Language, override string) (ServerCommand, bool) {\n\tbinaries := lang.Binaries\n\tif override != "" {\n\t\tbinary, err := selectBinaryOverride(override, binaries)\n\t\tif err != nil {\n\t\t return ServerCommand{}, false // Safe rejection on invalid binary name\n\t\t}\n\t\tbinaries = []Binary{binary}\n\t}\n\t// ...\n}\n

Exploitation Methodology

An attacker exploits this vulnerability by distributing a repository containing a malicious .knowns/config.json configuration file. The target workspace configuration is set to point the LSP binary to a command interpreter or local script.\n\nTo demonstrate this concept, a workspace is configured with the following content within .knowns/config.json:\n\njson\n{\n "settings": {\n "lsp": {\n "languages": {\n "go": {\n "binary": "/bin/sh"\n }\n }\n }\n }\n}\n\n\nWhen the victim opens the repository containing this file with knowns, the workspace manager reads the configuration. During the language server initialization phase, the workspace engine attempts to run the binary identified as /bin/sh to launch the language server, leading to execution of the shell instead of the language tool. If the attacker also bundles a target execution payload, they can force execution of specific scripts by specifying path parameters.

Impact Assessment

The vulnerability poses a high risk to environments running knowns on untrusted repositories. Successful exploitation results in arbitrary command execution under the context of the user running the application.\n\nAccording to CVSS v4.0 metrics, this vulnerability has a base score of 8.5. The attack vector is local because the user must interact with and open the directory containing the malicious configuration file. There are no special execution conditions, and no administrative privileges are required to exploit the flaw.\n\nBecause the code runs within the user's active session, the attacker gains full read, write, and execute permissions over all files accessible to that user account. This can lead to credential theft, compromise of sensitive source code, and subsequent privilege escalation on the host system.

Remediation & Mitigation Guidance

The primary remediation strategy is upgrading the application to version 0.30.0 or higher. Version 0.30.0 introduces structural input validation and prevents unauthorized binary overrides by rejecting non-registered executable names.\n\nIn environments where upgrading is not immediately possible, organizations must implement operational controls. Users must refrain from opening directories or repositories from untrusted sources, such as unverified public code repositories.\n\nAdditionally, system administrators should monitor process creation logs. Security tools should flag any instances where the application processes initiate system interpreters or command shells directly upon workspace loading.

Technical Appendix

CVSS Score
8.5/ 10
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Probability
0.21%
Top 89% most exploited

Affected Systems

knowns

Affected Versions Detail

Product
Affected Versions
Fixed Version
knowns
knowns-dev
< 0.30.00.30.0
AttributeDetail
CWE IDCWE-78
Attack VectorLocal
CVSS v4.0 Base Score8.5
EPSS Score0.00212
Exploit Statusnone/low
ImpactArbitrary Code Execution (ACE)

MITRE ATT&CK Mapping

T1059Command and Scripting Interpreter
Execution
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The application constructs an OS command using externally-influenced input without neutralizing or validating the input before passing it to execution subsystems.

Vulnerability Timeline

Security patch committed in d3989829fb5095666d23d005b2f78a082832a396
2026-08-13
GitHub Security Advisory GHSA-mc52-mwq4-vfx3 published
2026-09-07
Release of version 0.30.0 containing the fix
2026-09-07

References & Sources

  • [1]GitHub Security Advisory GHSA-mc52-mwq4-vfx3
  • [2]Fix Commit
  • [3]NVD Detail

More Reports

•about 1 hour ago•CVE-2026-105849
7.7

CVE-2026-105849: Sensitive Data Exposure and Privilege Escalation in Payload CMS API Key Authentication

A sensitive data exposure vulnerability in Payload CMS allows authenticated low-privilege users to retrieve decrypted, plaintext API keys of other users, including administrators, leading to full administrative account takeover and privilege escalation.

Amit Schendel
Amit Schendel
3 views•5 min read
•about 3 hours ago•CVE-2026-105854
8.7

CVE-2026-105854: Regular Expression Denial of Service (ReDoS) and Uncontrolled Resource Consumption in Payload CMS

Payload CMS, a popular open-source headless Content Management System, contains a critical Regular Expression Denial of Service (ReDoS) and uncontrolled resource consumption vulnerability in versions prior to 3.90.0 and canary versions prior to 4.0.0-canary.34. Due to nested quantifiers in the multipart boundary regex validation pattern, and the absence of streaming backpressure controls, remote attackers can trigger catastrophic backtracking and memory exhaustion. This blocks the single-threaded Node.js event loop, resulting in a persistent and complete Denial of Service (DoS).

Amit Schendel
Amit Schendel
4 views•6 min read
•about 4 hours ago•CVE-2026-105855
7.6

CVE-2026-105855: Privilege Escalation via Improper Access Control on Password Fields in Payload CMS

An Improper Access Control vulnerability (CWE-284) in Payload CMS prior to version 3.90.0 and 4.0.0-canary.34 allows authenticated, low-privileged users to bypass field-level access control restrictions and overwrite the password of other accounts, leading to complete account takeover and privilege escalation.

Alon Barad
Alon Barad
8 views•6 min read
•about 5 hours ago•CVE-2026-105804
5.7

CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS

Payload CMS was discovered to use an insecure default configuration for its password-hashing mechanism. The system requested a 512-byte key from PBKDF2-HMAC-SHA256 with 25,000 iterations, creating a severe cryptographic asymmetry. While the defending server sequentially computed 16 blocks of key material (equivalent to 400,000 internal iterations), an offline attacker only needed to compute the first 32-byte block to verify password guesses. This allowed offline attackers to crack stolen database hashes 16 times faster than intended by the security design.

Alon Barad
Alon Barad
6 views•6 min read
•about 6 hours ago•GHSA-WQ5F-XC86-PV6W
7.8

CVE-2026-96889: Remote Code Execution via Use-After-Free in librsvg (VectorFreed)

VectorFreed identifies a critical Use-After-Free (UAF) memory corruption vulnerability in librsvg (CVE-2026-96889), which manifests when parsing structured SVG documents containing nested XML inclusions (XIncludes) and duplicate entity declarations. The flaw results from an entity ownership conflict where librsvg prematurely deallocates an xmlEntity structure still actively referenced by the underlying libxml2 parser context. When transitively compiled into downstream applications such as the high-performance sharp image processing library, this vulnerability facilitates denial of service and unauthenticated remote code execution on the host operating system.

Amit Schendel
Amit Schendel
6 views•8 min read
•about 8 hours ago•CVE-2026-102275
6.5

CVE-2026-102275: Public/Private Key Identity Confusion in PyJWT OKP JWK Processing

CVE-2026-102275 (GHSA-x33g-cr3x-6449) is a public/private key identity confusion vulnerability in PyJWT versions 2.1.0 through 2.14.0. When importing Octet Key Pair (OKP) JSON Web Keys (JWKs) representing Ed25519 or Ed448 curves, PyJWT fails to verify that the public parameter 'x' matches the private parameter 'd'. An attacker can construct a hybrid JWK combining a victim's public key with the attacker's private key. In protocols like DPoP that bind sessions via public key thumbprints, this allows the attacker to authenticate as the victim while signing proofs with their own private key, fully bypassing sender-constrained security guarantees.

Amit Schendel
Amit Schendel
7 views•6 min read