VDB
CVE-2026-22687
CVE-2026-22687
PUBLISHED
CVSS 5.599999904632568 MEDIUM
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass techniques to evade query restrictions and obtain sensitive information from the target server and database. This issue has been patched in version 0.2.5.
EPSS 0.39% · 32.2th percentile
Risk Scores
CVSS 3.1
5.599999904632568
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.39%
32.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | Tencent/WeKnora | 0, 0 |
| tencent | weknora | 0, 0 |
| Tencent | WeKnora | < 0.2.5, * |
Timeline
- Jan 9, 2026 CVE Published
- Jan 10, 2026 EPSS Score
- Jan 10, 2026 PoC Published
- Jan 10, 2026 PoC Published
- Jan 10, 2026 PoC Published
- Jan 10, 2026 PoC Published
- Jan 10, 2026 PoC Published
- Jan 13, 2026 EPSS Score
- Jan 13, 2026 PoC Published
- Jan 17, 2026 EPSS Score
- Jan 20, 2026 EPSS Score
- Jan 24, 2026 EPSS Score
References
- https://github.com/Tencent/WeKnora/commit/da55707022c252dd2c20f8e18145b2d899ee06a1 url
- https://github.com/Tencent/WeKnora/security/advisories/GHSA-pcwc-3fw3-8cqv url
- https://nvd.nist.gov/vuln/detail/CVE-2026-22687 advisory
- https://pkg.go.dev/vuln/GO-2026-4293 url
- https://github.com/Tencent/WeKnora package