weknora vulnerabilities
CVEs whose affected-version data names the weknora package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-91750Medium· 6.5PoCWeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs
WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation…
▾ TwilightTencent · WeKnoraEPSS 0.44%via NVD
CVE-2025-11046High· 7.3A security flaw has been discovered in Tencent WeKnora 0.1.0
A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery…
▾ Twilighttencent · weknoraEPSS 0.47%via NVD