CVE-2026-88939
Last modified
CVE-2026-88939 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| knowns-dev | knowns | <= 0.33.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-88939?
How severe is CVE-2026-88939?
How do I fix CVE-2026-88939?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-88926The VikRentItems Flexible Rental Management System WordPress…8.6
- CVE-2026-88929The Product Badge, Label, Countdown Timer for WooCommerce W…5.3
- CVE-2026-8893The Express Payment For Stripe plugin for WordPress is vulne…6.4
- CVE-2026-88932multer is a Node.js middleware for handling multipart/form-d…5.3
- CVE-2026-88937knowns through 0.33.0 fails to properly validate template de…8.8
- CVE-2026-88938knowns through 0.33.0 fails to confine the path argument of …6.5
- CVE-2026-8894The iWR Tooltip plugin for WordPress is vulnerable to Stored…6.4
- CVE-2026-88940knowns through 0.33.0 fails to validate the path query param…5.3
- CVE-2026-88944The Tutor LMS – eLearning and online course solution plugin …4.3
- CVE-2026-8895The kk blog card plugin for WordPress is vulnerable to Store…6.4
- CVE-2026-88952Improper Authentication vulnerability in team-alembic AshAut…9.1
- CVE-2026-88956The Botslab G980H dash camera firmware contains an authentic…6.8
Are you affected by CVE-2026-88939?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
