top of page
perceptive_background_267k.jpg

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulner…

Published:

9 januari 2026 om 23:00:00

Alert date:

10 januari 2026 om 13:10:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

WeKnora, an LLM-powered framework for document understanding and semantic retrieval, contains a command injection vulnerability in versions prior to 0.2.5. The vulnerability allows authenticated users to inject malicious commands into stdio_config.command/args within MCP stdio settings. This enables attackers to execute arbitrary subprocesses on the server using the injected values. The security issue affects the framework's ability to safely handle user input in configuration settings. Tencent has addressed this vulnerability by releasing a patch in version 0.2.5. Users are advised to upgrade to the latest version to mitigate the command injection risk.

Technical details

Mitigation steps:

Affected products:

WeKnora

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page