WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these injected values. This issue has been patched in version 0.2.5.
Metrics
Affected Vendors & Products
References
History
Mon, 12 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tencent
Tencent weknora |
|
| Vendors & Products |
Tencent
Tencent weknora |
Sat, 10 Jan 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these injected values. This issue has been patched in version 0.2.5. | |
| Title | WeKnora has Command Injection in MCP stdio test | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-01-10T03:41:59.952Z
Updated: 2026-01-12T17:20:43.431Z
Reserved: 2026-01-08T19:23:09.854Z
Link: CVE-2026-22688
Updated: 2026-01-12T17:20:29.771Z
Status : Awaiting Analysis
Published: 2026-01-10T04:16:01.837
Modified: 2026-01-13T14:03:18.990
Link: CVE-2026-22688
No data.