knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-07 23:16
Updated : 2026-09-08 19:56
NVD link : CVE-2026-86540
Mitre link : CVE-2026-86540
CVE.ORG link : CVE-2026-86540
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
