Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22688

Опубликовано: 10 янв. 2026
Источник: nvd
CVSS3: 9.9
EPSS Низкий

Описание

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these injected values. This issue has been patched in version 0.2.5.

EPSS

Процентиль: 55%
0.00328
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.9
github
10 дней назад

WeKnora has Command Injection in MCP stdio test

EPSS

Процентиль: 55%
0.00328
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-77