highCVSS 7.8Vulnerability

CVE-2026-86540

## Overview A critical **Arbitrary Code Execution (ACE)** vulnerability exists in the Knowns Language Server Protocol (LSP) detection and startup pipeline. The system blindly trusts the `settings.lsp.languages.<lang>.binary` field defined in the project-level `.knowns/config.json` file. Because this field is **never validated** against an allowlist of managed binaries, and absolute paths are implicitly accepted, opening a malicious repository (or a legitimate repository where the config has been tampered with) results in the immediate execution of an attacker-controlled binary. The payload is executed **twice** per session: once during the initial `runVersionCheck` (health check), and again when the LSP server process is spawned via `Server.Start()`. When chained with the previously identified Config Overwrite vulnerabilities, this flaw yields a fully unauthenticated Remote Code Execution chain. ## Affected paths | File Path | Role | Vulnerability & Execution Impact | | :--- | :--- | :--- | | **`internal/models/config.go`** | Validation Gap | **Missing Binary Validation (CWE-829):** `ProjectSettings.Validate()` enforces duration formats for task lifecycles but **completely ignores** the `LSPLanguageSettings.Binary` field. Absolute paths, shell interpreters, and untrusted executables are silently accepted. | | **`internal/lsp/detect.go`** | Execution Sink #1 | **Unsanitized Health Check Execution:** `Detector.resolve()` passes the unvalidated override to `exec.LookPath()`, then invokes `runVersionCheck()` which blindly calls `cmd.Run()` on the attacker-controlled binary with `CheckArgs`. | | **`internal/lsp/server.go`** | Execution Sink #2 | **Unsanitized LSP Server Spawn:** `Server.Start()` passes the resolved binary path to `knownsprocess.Command()` and spawns it as a long-running background process via `cmd.Start()`, executing the payload a second time. | ## Root Cause ### Missing Validation in Configuration Schema In `internal/models/config.go`, the `Proje

Properties

severity
high
summary
knowns OS Command Injection via Insecure LSP Binary Path Config in .knowns/config.json
cvss_score
7.8
retrieved_at
2026-10-07T00:37:23+00:00
ghsa_published
2026-10-06T18:58:38Z
source_url
https://github.com/advisories/GHSA-mc52-mwq4-vfx3
ghsa_updated
2026-10-06T18:58:40Z
ghsa_id
GHSA-mc52-mwq4-vfx3
last_source
GitHub Advisory Database
cve_id
CVE-2026-86540
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
signal_observed_at
2026-10-07T00:37:23+00:00
is_ghsa_only
false

Related Entities (7)

VULNERABLE_TO (1)

←[Software]npm/knowns

AFFECTS (1)

→[Software]npm/knowns

HAS_WEAKNESS (4)

→[Weakness]Inclusion of Functionality from Untrusted Control Sphere
→[Weakness]Uncontrolled Search Path Element
→[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
→[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86540 (CVSS 7.8) — Ninja Signal Threat Intelligence | Ninja Signal