


Perceptive Security
SOC/SIEM Consultancy

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulner…
Published:
9 januari 2026 om 23:00:00
Alert date:
10 januari 2026 om 13:10:58
Source:
nvd.nist.gov
WeKnora, an LLM-powered framework for document understanding and semantic retrieval, contains a command injection vulnerability in versions prior to 0.2.5. The vulnerability allows authenticated users to inject malicious commands into stdio_config.command/args within MCP stdio settings. This enables attackers to execute arbitrary subprocesses on the server using the injected values. The security issue affects the framework's ability to safely handle user input in configuration settings. Tencent has addressed this vulnerability by releasing a patch in version 0.2.5. Users are advised to upgrade to the latest version to mitigate the command injection risk.
Technical details
Mitigation steps:
Affected products:
WeKnora
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-22688
https://github.com/Tencent/WeKnora/commit/f7900a5e9a18c99d25cec9589ead9e4e59ce04bb
https://github.com/Tencent/WeKnora/security/advisories/GHSA-78h3-63c4-5fqc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
