CVE-2026-88899

Summary

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.

Affected Software

VendorProductVersion RangeStatus
knowns-devknowns0 < 0.31.0affected
knowns-devknowns0.31.0unaffected

Weaknesses

  • CWE-73: External Control of File Name or Path

References