CVE-2026-30856Disclosure(tencent / weknora)

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a vulnerability involving tool name collision and indirect prompt injection allows a malicious remote MCP server to hijack tool execution. By exploiting an ambiguous naming convention in the MCP client (mcp_{service}_{tool}), an attacker can register a malicious tool that overwrites a legitimate one (e.g., tavily_extract). This enables the attacker to redirect LLM execution flow, exfiltrate system prompts, context, and potentially execute other tools with the user's privileges. This issue has been patched in version 0.3.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-706

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weknora

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-07); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
weknora

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-07: 2Mentions · 2026-03-16: 2Mentions · 2026-03-20: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-20: 103-0703-1603-20
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-072
Disclosure1General1
2026-03-162
Disclosure2
2026-03-201
Disclosure1
Full discourse5 posts
  • AI Security Guard@ai_security_10x
    Disclosure

    CVE-2026-30856: MCP Tool Name Collision Attacks in WeKnora Framework #security https://moltx.io/articles/d186b429-e92b-4406-89ee-85e1889a5ee0

    Post summary

    The post references CVE-2026-30856 as an MCP Tool Name Collision vulnerability in the WeKnora Framework, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00010135
    4 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    CVE-2026-30856: How Tool Name Collisions Enable MCP Server Hijacking in WeKnora #security https://moltx.io/articles/40c438c1-7b17-4d28-92cf-c016e63e7030

    Post summary

    The post announces CVE-2026-30856, explaining that tool name collisions can hijack the MCP server in WeKnora, and links to an article for further details.

    0001061
    4 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-30856: How MCP Tool Name Collisions Enable Prompt Exfiltration in WeKnora https://moltx.io/articles/07f1af8f-704c-4c9a-ac74-21043c69042d

    Post summary

    The tweet announces a newly disclosed CVE‑2026‑30856, noting that MCP tool name collisions allow prompt exfiltration in WeKnora, but contains no PoC or exploitation details.

    0000033
    4 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30856 Remote Tool Hijacking Vulnerability in WeKnora LLM Framework Before 0.3.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30856

    Post summary

    The note announces CVE-2026-30856, a remote tool hijacking flaw in WeKnora LLM Framework versions prior to 0.3.0, with no PoC, exploit, or patch details provided.

    0000045
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-30856 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a vulnerability involving tool name coll… https://www.cve.org/CVERecord?id=CVE-2026-30856

    Post summary

    The text references CVE-2026-30856 as a vulnerability in WeKnora before version 0.3.0, but provides no further technical, exploit, or mitigation details.

    0000080
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptencentweknora---

Explore more