Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-86540

HIGH NVD
CVSS Score 7.8
Severity HIGH
Published Sep 07, 2026
Vendor unknown

Description

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.

References