Tencent
Tencent Weknora: vulnerabilidades y CVE
Tencent Weknora tiene 13 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses12
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-91750 | Alta (7.1) | 0.44% | — | 15 sept 2026 | WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass… |
| CVE-2026-8786 | Baja (2.1) | 0.42% | — | 18 may 2026 | A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component Config API… |
| CVE-2026-30861 | Alta (8.8) | 2.5% | — | 7 mar 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution (RCE) vulnerability exists in… |
| CVE-2026-30860 | Crítica (9.8) | 0.74% | — | 7 mar 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query… |
| CVE-2026-30859 | Media (6.5) | 0.36% | — | 7 mar 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control vulnerability in the database query tool allows any authenticated… |
| CVE-2026-30858 | Alta (7.5) | 0.48% | — | 7 mar 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a DNS rebinding vulnerability in the web_fetch tool allows an unauthenticated attacker to… |
| CVE-2026-30857 | Media (5.3) | 0.28% | — | 7 mar 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authorization bypass in the knowledge base copy endpoint allows any… |
| CVE-2026-30856 | Alta (7.6) | 0.29% | — | 7 mar 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a vulnerability involving tool name collision and indirect prompt injection allows a malicious… |
| CVE-2026-30855 | Alta (8.8) | 0.46% | — | 7 mar 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any… |
| CVE-2026-30247 | Alta (7.5) | 0.35% | — | 7 mar 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, the application's "Import document via URL" feature is vulnerable to Server-Side Request… |
| CVE-2026-22688 | Alta (8.8) | 2.0% | — | 10 ene 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject… |
| CVE-2026-22687 | Crítica (9.8) | 0.39% | — | 10 ene 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due… |
| CVE-2025-11046 | Media (5.5) | 0.47% | — | 26 sept 2025 | A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in… |