PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-88899 knowns-dev CVE debrief

CVE-2026-88899 is a critical vulnerability in knowns versions before 0.31.0, allowing remote attackers to execute file operations outside the project root on the host system via the x-opencode-directory request header in the /api/opencode proxy endpoint. This vulnerability has a CVSS score of 9.3 and is considered critical. Defenders should assess exposure and prioritize upgrading to version 0.31.0 or later. The vulnerability exists due to improper validation of the x-opencode-directory request header, which allows attackers to supply arbitrary directory paths.

Vendor
knowns-dev
Product
knowns
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-11
Advisory published
2026-09-10
Advisory updated
2026-09-11

Who should care

Defenders responsible for systems using knowns versions before 0.31.0 should assess exposure and prioritize upgrading to version 0.31.0 or later. This includes operators, platform administrators, vulnerability management teams, and security teams. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change控制.

Why it matters

CVE-2026-88899 is a critical vulnerability in knowns versions before 0.31.0, allowing remote attackers to execute file operations outside the project root on the host system. Defenders should prioritize verifying exposure and upgrading to version 0.31.0 or later.

  • Potential file operations outside the project root on the host system
  • Possible execution of arbitrary file operations by remote attackers
  • Verification of knowns versions before 0.31.0 is necessary to determine exposure
  • Upgrading to version 0.31.0 or later is necessary to remediate the vulnerability

Technical summary

The vulnerability exists in the /api/opencode proxy endpoint of knowns versions before 0.31.0, where the x-opencode-directory request header is not properly validated, allowing remote attackers to execute file operations outside the project root on the host system. This vulnerability has a CVSS score of 9.3 and is considered critical. The affected versions of knowns are before 0.31.0, and defenders should prioritize verifying exposure and upgrading to version 0.31.0 or later. The vulnerability is caused by the lack of proper validation of the x-opencode-directory request header.

Defensive priority

Defenders should prioritize verifying exposure of knowns versions before 0.31.0 and upgrading to version 0.31.0 or later.

Recommended defensive actions

  • Verify knowns versions before 0.31.0 are not in use
  • Upgrade to knowns version 0.31.0 or later
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its critical CVSS score of 9.3 and the affected versions of knowns. The vulnerability is caused by the lack of proper validation of the x-opencode-directory request header in the /api/opencode proxy endpoint. Defenders should verify exposure by checking for knowns versions before 0.31.0 and prioritize upgrading to version 0.31.0 or later. The CVE Program record and NVD detail page provide additional information on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-88899 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-88899

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-88899 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88899

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.