Vulnerabilities
Vulnerable Software
Tencent:  >> Weknora  >> 0.1.5  Security Vulnerabilities
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass techniques to evade query restrictions and obtain sensitive information from the target server and database. This issue has been patched in version 0.2.5.
CVSS Score
8.1
EPSS Score
0.001
Published
2026-01-10
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these injected values. This issue has been patched in version 0.2.5.
CVSS Score
9.9
EPSS Score
0.003
Published
2026-01-10


Contact Us

Shodan ® - All rights reserved