github.com/Tencent/WeKnora
Go10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/Tencent/WeKnorapage 1 of 1
- CVE-2026-22687CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.2.52026-01-10
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient back…
- CVE-2026-22688HIGHCVSS 8.8EG 8.8✓ Fixed in 0.2.52026-01-10
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args int…
- CVE-2026-30247HIGHCVSS 7.5EG 7.5✓ Fixed in 0.2.122026-03-07
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, the application's "Import document via URL" feature is vulnerable to Server-Side Request Forgery (SSRF) through H…
- CVE-2026-30855HIGHCVSS 8.8EG 8.8✓ Fixed in 0.3.12026-03-07
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to rea…
- CVE-2026-30856HIGHCVSS 7.6EG 7.6✓ Fixed in 0.3.02026-03-07
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a vulnerability involving tool name collision and indirect prompt injection allows a malicious remote MCP server …
- CVE-2026-30857MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.3.02026-03-07
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authorization bypass in the knowledge base copy endpoint allows any authenticated user to clone (du…
- CVE-2026-30858HIGHCVSS 7.5EG 7.5✓ Fixed in 0.3.02026-03-07
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a DNS rebinding vulnerability in the web_fetch tool allows an unauthenticated attacker to bypass URL validation an…
- CVE-2026-30859MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.2.122026-03-07
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control vulnerability in the database query tool allows any authenticated tenant to read sensitiv…
- CVE-2026-30860CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.2.122026-03-07
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validat…
- CVE-2026-30861HIGHCVSS 8.8EG 8.8✓ Fixed in 0.2.102026-03-07
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution (RCE) vulnerability exists in the MCP stdio configur…
Check whether github.com/Tencent/WeKnora is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/Tencent/WeKnora CVEs against the assets you own.
Start Free Scan →