Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

WeKnora MCP tool name collision enables prompt injection and tool hijacking

A vulnerability in Tencent's WeKnora LLM document-understanding framework before version 0.3.0 let a malicious remote MCP server register a tool that overwrites a legitimate one due to an ambiguous mcp_{service}_{tool} naming convention. Combined with indirect prompt injection, this allowed attackers to hijack LLM execution flow, exfiltrate system prompts and context, and run other tools with the user's privileges.

Disclosed 7 March 2026 · Record updated 13 September 2026

Impact

Attacker-controlled MCP server could redirect tool execution, exfiltrate system prompts and context, and invoke tools with the user's privileges in affected WeKnora deployments.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30856