CVE-2026-22688

CRITICAL

WeKnora < 0.2.5 - Authenticated Command Injection via stdio_config.command/args

Title source: llm
STIX 2.1

Description

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these injected values. This issue has been patched in version 0.2.5.

Scores

CVSS v3 9.9
EPSS 0.0175
EPSS Percentile 74.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (2)
tencent/weknora < 0.2.5
Tencent/WeKnora 0 - 0.2.5Go
Published Jan 10, 2026
Tracked Since Feb 18, 2026