← Back to browse · API

CVE-2026-22688

Severity
CRITICAL
CVSS
10.0
EPSS
0.01777
Risk score
40.62
CISA KEV
No
PoC
Yes
Published
2026-01-10
Modified
2026-01-12
First seen
2026-08-07
Aliases
EUVD-2026-1695, GHSA-78H3-63C4-5FQC
Products
Tencent:WeKnora < 0.2.5, linux, suse
Sources
packetstorm e760ebd193aaec6c0d4acb9c|CVE-2026-22688
euvd EUVD-2026-1695

Description

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these injected values. This issue has been patched in version 0.2.5.

References