WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass techniques to evade query restrictions and obtain sensitive information from the target server and database. This issue has been patched in version 0.2.5.
📦
weknora
Vendor: tencent
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
2
Remote Access
Total CVEs
24
Total Indexed
Avg. EPSS
0.12%
Exploit Prob.
Security Vulnerability Index
Page 2 / 3
5.6
CVSS
Severity: MEDIUM
5.5
CVSS
A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. It is advisable to upgrade the affected component. The vendor responds: "We have confirmed that the issue mentioned in the report does not exist in the latest releases".
Severity: MEDIUM