Tencent WeKnora agent flaws allow prompt-based DB access and command injection
Two vulnerabilities in Tencent's WeKnora LLM document-understanding framework prior to version 0.2.5 let attackers use prompt-based bypass techniques against the Agent service's database query tool to extract sensitive server and database data (CVE-2026-22687), and let authenticated users inject commands into MCP stdio settings to run subprocesses on the server (CVE-2026-22688). Both were patched in version 0.2.5.
Disclosed 10 January 2026 · Record updated 13 September 2026
Impact
Attackers could bypass query restrictions to obtain sensitive information from the target server and database, and authenticated users could cause the server to execute arbitrary subprocesses via injected MCP stdio command/args.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-22687
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-22688
