knowns before 0.30.0 Arbitrary Code Execution via LSP Binary
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
knowns-dev · knownsReferences
https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/lsp/detect.go#L128-L157https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/models/config.go#L205-L216https://github.com/knowns-dev/knowns/commit/d3989829fb5095666d23d005b2f78a082832a396https://github.com/knowns-dev/knowns/releases/tag/v0.30.0https://github.com/knowns-dev/knowns/security/advisories/GHSA-mc52-mwq4-vfx3https://www.vulncheck.com/advisories/knowns-before-0.30.0-arbitrary-code-execution-via-lsp-binary