


Perceptive Security
SOC/SIEM Consultancy

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vuln…
Published:
6 March 2026 at 23:00:00
Alert date:
7 March 2026 at 18:01:53
Source:
nvd.nist.gov
Database & Storage, Web Technologies, Emerging Technologies
WeKnora, an LLM-powered document understanding framework, contains a critical remote code execution vulnerability in versions prior to 0.2.12. The vulnerability exists in the database query functionality where validation fails to inspect child nodes in PostgreSQL array and row expressions. Attackers can bypass SQL injection protections by smuggling dangerous PostgreSQL functions and chaining them with large object operations. This allows unauthenticated attackers to achieve arbitrary code execution on the database server with database user privileges. The issue has been patched in version 0.2.12.
Technical details
Mitigation steps:
Affected products:
WeKnora
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30860
https://github.com/Tencent/WeKnora/security/advisories/GHSA-8w32-6mrw-q5wv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
