CVE-2026-86540
## Overview A critical **Arbitrary Code Execution (ACE)** vulnerability exists in the Knowns Language Server Protocol (LSP) detection and startup pipeline. The system blindly trusts the `settings.lsp.languages.<lang>.binary` field defined in the project-level `.knowns/config.json` file. Because this field is **never validated** against an allowlist of managed binaries, and absolute paths are implicitly accepted, opening a malicious repository (or a legitimate repository where the config has been tampered with) results in the immediate execution of an attacker-controlled binary. The payload is executed **twice** per session: once during the initial `runVersionCheck` (health check), and again when the LSP server process is spawned via `Server.Start()`. When chained with the previously identified Config Overwrite vulnerabilities, this flaw yields a fully unauthenticated Remote Code Execution chain. ## Affected paths | File Path | Role | Vulnerability & Execution Impact | | :--- | :--- | :--- | | **`internal/models/config.go`** | Validation Gap | **Missing Binary Validation (CWE-829):** `ProjectSettings.Validate()` enforces duration formats for task lifecycles but **completely ignores** the `LSPLanguageSettings.Binary` field. Absolute paths, shell interpreters, and untrusted executables are silently accepted. | | **`internal/lsp/detect.go`** | Execution Sink #1 | **Unsanitized Health Check Execution:** `Detector.resolve()` passes the unvalidated override to `exec.LookPath()`, then invokes `runVersionCheck()` which blindly calls `cmd.Run()` on the attacker-controlled binary with `CheckArgs`. | | **`internal/lsp/server.go`** | Execution Sink #2 | **Unsanitized LSP Server Spawn:** `Server.Start()` passes the resolved binary path to `knownsprocess.Command()` and spawns it as a long-running background process via `cmd.Start()`, executing the payload a second time. | ## Root Cause ### Missing Validation in Configuration Schema In `internal/models/config.go`, the `Proje
Properties
- severity
- high
- summary
- knowns OS Command Injection via Insecure LSP Binary Path Config in .knowns/config.json
- cvss_score
- 7.8
- retrieved_at
- 2026-10-07T00:37:23+00:00
- ghsa_published
- 2026-10-06T18:58:38Z
- source_url
- https://github.com/advisories/GHSA-mc52-mwq4-vfx3
- ghsa_updated
- 2026-10-06T18:58:40Z
- ghsa_id
- GHSA-mc52-mwq4-vfx3
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-86540
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- signal_observed_at
- 2026-10-07T00:37:23+00:00
- is_ghsa_only
- false
Related Entities (7)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (4)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph