CVE-2026-86439 with a CVSS score of 8.8 is a Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary.md file read, write, and deletion in MCP Docs + Memory Tools. Verified. Multiple Unrestricted Path Traversal vulnerabilities affecting knowns versions <= 0.29.1 exist in the Knowns MCP docs and memory tools, allowing arbitrary file read, write, and deletion operations outside the project sandbox. The storage layer functions (Get, Create, Update, Rename, Delete) in both doc_store.go and memory_store.go concatenate user-controlled paths with filepath.Join without any containment validation. Additionally, the docs.update action with a newPath parameter performs a file deletion via Rename, but is classified as CapWrite in the permission registry rather than CapDelete. This allows an attacker with a read-write-no-delete preset to bypass deletion restrictions and destroy arbitrary files outside the project root. The attack vector includes four phases: 1. Arbitrary File Read, 2. Arbitrary File Write, 3. Arbitrary File Delete, and 4. Memory File Read/Write. Affected versions include all versions prior to the fix in MCP Docs + Memory Tools. This vulnerability can lead to business impact due to unauthorized access to sensitive data and potential data loss or corruption.
We recommend you to update Knowns to version 0.30.0.[/subscribe_to_unlock_form]
CVE-2026-86439 with a CVSS score of 8.8 is a Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary.md file read, write, and deletion in MCP Docs + Memory Tools. Verified. Multiple Unrestricted Path Traversal vulnerabilities affecting knowns versions <= 0.29.1 exist in the Knowns MCP docs and memory tools, allowing arbitrary file read, write, and deletion operations outside the project sandbox. The storage layer functions (Get, Create, Update, Rename, Delete) in both doc_store.go and memory_store.go concatenate user-controlled paths with filepath.Join without any containment validation. Additionally, the docs.update action with a newPath parameter performs a file deletion via Rename, but is classified as CapWrite in the permission registry rather than CapDelete. This allows an attacker with a read-write-no-delete preset to bypass deletion restrictions and destroy arbitrary files outside the project root. The attack vector includes four phases: 1. Arbitrary File Read, 2. Arbitrary File Write, 3. Arbitrary File Delete, and 4. Memory File Read/Write. Affected versions include all versions prior to the fix in MCP Docs + Memory Tools. This vulnerability can lead to business impact due to unauthorized access to sensitive data and potential data loss or corruption.
We recommend you to update Knowns to version 0.30.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]