Skip to main content

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CVE-2026-22688

Severity High
Score 8.8/10

Summary

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject "stdio_config.command/args" into MCP "stdio" settings, causing the server to execute subprocesses using these injected values. This issue has been patched in version 0.2.5.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • HIGH

CWE-77 - Command Injection

A command injection attack involves injecting an operating system command through the data input, which gets executed on the host operating system with the privileges of the victimized application. The impact of a command injection attack may range from loss of data confidentiality and integrity to unauthorized remote access to the hosting system. The attack may cause serious data breaches and system takeover.

Advisory Timeline

  • Published