VDB

CVE-2026-22687

CVE-2026-22687 PUBLISHED CVSS 5.599999904632568 MEDIUM

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass techniques to evade query restrictions and obtain sensitive information from the target server and database. This issue has been patched in version 0.2.5.

EPSS 0.04% · 11.6th percentile

Risk Scores

CVSS 3.1
5.599999904632568
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.04%
11.6th percentile

Affected Products

VendorProductVersions
github.comTencent/WeKnora0, 0
tencentweknora0, 0
TencentWeKnora< 0.2.5, *

Timeline

  • Jan 9, 2026 CVE Published
  • Jan 10, 2026 EPSS Score
  • Jan 10, 2026 PoC Published
  • Jan 10, 2026 PoC Published
  • Jan 10, 2026 PoC Published
  • Jan 10, 2026 PoC Published
  • Jan 10, 2026 PoC Published
  • Jan 13, 2026 EPSS Score
  • Jan 13, 2026 PoC Published
  • Jan 16, 2026 EPSS Score
  • Jan 19, 2026 EPSS Score
  • Jan 22, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›