CVE-2026-22688

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these injected values. This issue has been patched in version 0.2.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tencent:weknora:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:20

Type Values Removed Values Added
Summary
  • (es) WeKnora es un framework impulsado por LLM diseñado para la comprensión profunda de documentos y la recuperación semántica. Antes de la versión 0.2.5, existe una vulnerabilidad de inyección de comandos que permite a los usuarios autenticados inyectar stdio_config.command/args en la configuración de stdio de MCP, lo que provoca que el servidor ejecute subprocesos utilizando estos valores inyectados. Este problema ha sido parcheado en la versión 0.2.5.

22 Jan 2026, 14:39

Type Values Removed Values Added
References () https://github.com/Tencent/WeKnora/commit/f7900a5e9a18c99d25cec9589ead9e4e59ce04bb - () https://github.com/Tencent/WeKnora/commit/f7900a5e9a18c99d25cec9589ead9e4e59ce04bb - Patch
References () https://github.com/Tencent/WeKnora/security/advisories/GHSA-78h3-63c4-5fqc - () https://github.com/Tencent/WeKnora/security/advisories/GHSA-78h3-63c4-5fqc - Exploit, Vendor Advisory
CPE cpe:2.3:a:tencent:weknora:*:*:*:*:*:*:*:*
First Time Tencent weknora
Tencent

12 Jan 2026, 18:15

Type Values Removed Values Added
References () https://github.com/Tencent/WeKnora/security/advisories/GHSA-78h3-63c4-5fqc - () https://github.com/Tencent/WeKnora/security/advisories/GHSA-78h3-63c4-5fqc -

10 Jan 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-10 04:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22688

Mitre link : CVE-2026-22688

CVE.ORG link : CVE-2026-22688


JSON object : View

Products Affected

tencent

  • weknora
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')