CVE-2026-30247
MEDIUMWeKnora < 0.2.12 - Server-Side Request Forgery via Redirect Chain Bypass
Title source: llmDescription
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, the application's "Import document via URL" feature is vulnerable to Server-Side Request Forgery (SSRF) through HTTP redirects. While the backend implements comprehensive URL validation (blocking private IPs, loopback addresses, reserved hostnames, and cloud metadata endpoints), it fails to validate redirect targets. An attacker can bypass all protections by using a redirect chain, forcing the server to access internal services. Additionally, Docker-specific internal addresses like host.docker.internal are not blocked. This issue has been patched in version 0.2.12.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://github.com/Tencent/WeKnora/security/advisories/GHSA-595m-wc8g-6qgc
Scores
CVSS v3
5.9
EPSS
0.0039
EPSS Percentile
30.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (2)
tencent/weknora
< 0.2.12
Tencent/WeKnora
0 - 0.2.12Go
Published
Mar 07, 2026
Tracked Since
Mar 07, 2026