CVE-2026-30860

CRITICAL LAB

WeKnora <0.2.12 - RCE via SQL Injection

Title source: llm

Description

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validation system fails to recursively inspect child nodes within PostgreSQL array expressions and row expressions, allowing attackers to bypass SQL injection protections. By smuggling dangerous PostgreSQL functions inside these expressions and chaining them with large object operations and library loading capabilities, an unauthenticated attacker can achieve arbitrary code execution on the database server with database user privileges. This issue has been patched in version 0.2.12.

Exploits (1)

github WORKING POC 1 stars
by exploitintel · cpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2026-30860

Scores

CVSS v3 9.9
EPSS 0.0021
EPSS Percentile 42.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Lab Environment

EIP LAB Lab screenshot
vulnerable docker pull ghcr.io/exploitintel/cve-2026-30860-vulnerable:latest
COMMUNITY
docker pull wechatopenai/weknora-ui:latest
docker pull ghcr.io/exploitintel/cve-2026-30860-vulnerable:latest
docker pull wechatopenai/weknora-docreader:latest
docker pull paradedb/paradedb:v0.18.9-pg17

Details

CWE
CWE-89
Status published
Products (2)
tencent/weknora < 0.2.12
Tencent/WeKnora 0 - 0.2.12Go
Published Mar 07, 2026
Tracked Since Mar 08, 2026