CVE-2026-86539 PUBLISHED

knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint

Assigner: VulnCheck
Reserved: 07.09.2026 Published: 07.09.2026 Updated: 07.09.2026

knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 6.9

Product Status

Vendor knowns-dev
Product knowns
Versions Default: unaffected
  • affected from 0 to 0.33.0 (incl.)

Credits

  • Tong Hoang Gia reporter
  • Nguyen Huy Hoang reporter

References

Problem Types

  • Server-Side Request Forgery (SSRF) CWE