top of page
perceptive_background_267k.jpg

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vuln…

Published:

6 March 2026 at 23:00:00

Alert date:

7 March 2026 at 18:01:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Web Technologies, Emerging Technologies

WeKnora, an LLM-powered document understanding framework, contains a critical remote code execution vulnerability in versions prior to 0.2.12. The vulnerability exists in the database query functionality where validation fails to inspect child nodes in PostgreSQL array and row expressions. Attackers can bypass SQL injection protections by smuggling dangerous PostgreSQL functions and chaining them with large object operations. This allows unauthenticated attackers to achieve arbitrary code execution on the database server with database user privileges. The issue has been patched in version 0.2.12.

Technical details

Mitigation steps:

Affected products:

WeKnora

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page