VDB
CVE-2026-22687
CVE-2026-22687
PUBLISHED
CVSS 5.599999904632568 MEDIUM
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass techniques to evade query restrictions and obtain sensitive information from the target server and database. This issue has been patched in version 0.2.5.
EPSS 0.04% · 11.6th percentile
Risk Scores
CVSS 3.1
5.599999904632568
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.04%
11.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | Tencent/WeKnora | 0, 0 |
| tencent | weknora | 0, 0 |
| Tencent | WeKnora | < 0.2.5, * |
Timeline
- Jan 9, 2026 CVE Published
- Jan 10, 2026 EPSS Score
- Jan 10, 2026 PoC Published
- Jan 10, 2026 PoC Published
- Jan 10, 2026 PoC Published
- Jan 10, 2026 PoC Published
- Jan 10, 2026 PoC Published
- Jan 13, 2026 EPSS Score
- Jan 13, 2026 PoC Published
- Jan 16, 2026 EPSS Score
- Jan 19, 2026 EPSS Score
- Jan 22, 2026 EPSS Score
References
- https://github.com/Tencent/WeKnora/security/advisories/GHSA-pcwc-3fw3-8cqv url
- https://github.com/Tencent/WeKnora/commit/da55707022c252dd2c20f8e18145b2d899ee06a1 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-22687 advisory
- https://github.com/Tencent/WeKnora package
- https://pkg.go.dev/vuln/GO-2026-4293 url