CVE-2026-88939
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
弱点类型
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
参考链接
- https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/permissions/guard.go#L104-L113
- https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/permissions/registry.go#L51-L54
- https://github.com/knowns-dev/knowns/security/advisories/GHSA-h73x-698r-qrvg
- https://www.vulncheck.com/advisories/knowns-through-0.33.0-authorization-bypass-via-project-set-bootstrap-exemption
- https://github.com/knowns-dev/knowns/security/advisories/GHSA-h73x-698r-qrvg