CVE-2026-30861Disclosure(tencent / weknora)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tencent weknora systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution (RCE) vulnerability exists in the MCP stdio configuration validation. The application allows unrestricted user registration, meaning any attacker can create an account and exploit the command injection flaw. Despite implementing a whitelist for allowed commands (npx, uvx) and blacklists for dangerous arguments and environment variables, the validation can be bypassed using the -p flag with npx node. This allows any attacker to execute arbitrary commands with the application's privileges, leading to complete system compromise. This issue has been patched in version 0.2.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weknora

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-07); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
weknora

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-07: 4Mentions · 2026-03-08: 2Mentions · 2026-03-12: 1Mentions · 2026-03-23: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-03-07: 3Technical Details · 2026-03-08: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-23: 103-0703-0803-1203-23
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-074
Disclosure3Patch1
2026-03-082
Disclosure1Patch1
2026-03-121
Disclosure1
2026-03-231
Disclosure1
Full discourse8 posts
  • maru@maru1151157
    Patch

    🚨 CVE-2026-30861 (CVSS: 9.9) CVE-2026-30861: WeKnora 0.2.5~0.2.10のMCP stdio設定検証に不正なコマンドインジェクション脆弱性。未認証ユーザーが-pフラグで任意コード実行可能。0.2.10に修正。 https://maruomosquit.com/vulnerability/CVE-2026-30861/ #脆弱性 #セキュリティ

    Post summary

    The post discloses CVE-2026-30861, identifies a command injection flaw, and notes that a patch is available in version 0.2.10, but gives no evidence of active exploitation or an exploit tool.

    00050484
    1.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30861 - WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation Intel Report: https://ift.tt/nXa7EDT

    Post summary

    The tweet announces the discovery of CVE-2026-30861, describing it as a remote code execution vulnerability via command injection, and provides a reference link, but no PoC, exploit code, or patch details are supplied.

    0001038
    344 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    WeKnora is affected by a critical command injection RCE (CVE-2026-30861) in its MCP Stdio Configuration Validation. Assess exposure and prepare for remediation. #infosec #RCE #vulnerability https://www.pulsepatch.io/posts/cve-2026-30861-weknora-rce-command-injection

    Post summary

    The post announces that WeKnora is vulnerable to a critical command‐injection RCE (CVE‑2026‑30861), urging assessment and remediation without indicating a PoC, active exploitation, or patch availability.

    0000031
    2 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30861 (CVSS:9.9, CRITICAL) is Analyzed. WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 ..https://nvd.nist.gov/vuln/detail/CVE-2026-30861 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2026‑30861, noting its critical CVSS score and linking to the NVD entry, but provides no PoC, exploit, or remediation details.

    0000020
    172 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30861 - Critical WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution ... https://www.thehackerwire.com/vulnerability/CVE-2026-30861/ https://t.co/BznOkiSsUV

    Post summary

    The post discloses CVE-2026-30861 as a critical unauthenticated remote code execution vulnerability in WeKnora versions 0.2.5 through before 0.2.10, but provides no PoC, exploit tool, active exploitation evidence, or patch details.

    0000041
    130 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30861 Unauthenticated Remote Code Execution in WeKnora Framework Versions 0.2.5-0.2.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30861

    Post summary

    CVE-2026-30861 exposes an unauthenticated remote code execution flaw in WeKnora Framework 0.2.5-0.2.9, with no PoC or exploit details provided.

    0000035
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30861 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated r… https://www.cve.org/CVERecord?id=CVE-2026-30861

    Post summary

    The text announces a new vulnerability (CVE‑2026‑30861) in the WeKnora LLM framework, noting an unauthenticated issue affecting releases 0.2.5 through prior to 0.2.10, without providing further technical, exploit, or mitigation details.

    0000074
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30861: CRITICAL] Unauthenticated RCE vulnerability in WeKnora framework versions 0.2.5-0.2.10 allows attackers to execute arbitrary commands. Ensure update to patch security flaw.#cve,CVE-2026-30861,#cybersecurity https://cvefind.com/CVE-2026-30861

    Post summary

    The tweet announces an unauthenticated RCE in WeKnora framework versions 0.2.5‑0.2.10 and urges users to apply the available patch.

    0000071
    599 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptencentweknora---

Explore more