Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Tencent WeKnora agent flaws allow prompt-based DB access and command injection

Two vulnerabilities in Tencent's WeKnora LLM document-understanding framework prior to version 0.2.5 let attackers use prompt-based bypass techniques against the Agent service's database query tool to extract sensitive server and database data (CVE-2026-22687), and let authenticated users inject commands into MCP stdio settings to run subprocesses on the server (CVE-2026-22688). Both were patched in version 0.2.5.

Disclosed 10 January 2026 · Record updated 13 September 2026

Impact

Attackers could bypass query restrictions to obtain sensitive information from the target server and database, and authenticated users could cause the server to execute arbitrary subprocesses via injected MCP stdio command/args.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-22687
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-22688