10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these injected values. This issue has been patched in version 0.2.5.
AI Analysis
Command injection vulnerability in WeKnora framework
Basic Information
ID
CVE-2026-22688
Source
GitHub_M
Published
Jan 10, 2026 at 03:41
Affected Product
Vendor
Tencent
Product
WeKnora
Version
< 0.2.5
Affected Versions
Tencent WeKnora < 0.2.5
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Tencent
Product
WeKnora
Version
< 0.2.5