Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Knowns-dev
Knowns-dev knowns |
|
| Vendors & Products |
Knowns-dev
Knowns-dev knowns |
Mon, 07 Sep 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification. | |
| Title | knowns before 0.30.0 Arbitrary Code Execution via LSP Binary | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T13:48:56.891Z
Reserved: 2026-09-07T22:18:47.705Z
Link: CVE-2026-86540
Updated: 2026-09-08T13:48:53.188Z
Status : Received
Published: 2026-09-07T23:16:53.723
Modified: 2026-09-08T14:17:34.960
Link: CVE-2026-86540
No data.
OpenCVE Enrichment
Updated: 2026-09-08T01:00:11Z