HIGHVulnerability
CVE-2026-88939
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
Properties
- severity
- HIGH
- score
- 8.3
- cve_id
- CVE-2026-88939
- signal_observed_at
- 2026-09-18T13:45:43+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
- published_at
- 2026-09-10T16:18:12.577
- last_modified
- 2026-09-15T15:17:26.583
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Incorrect Authorization
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph