blob: 36d7804be3ccfb2b124c8734e64d38dcf678bfba [file]
id: GO-2026-4292
modules:
- module: github.com/Tencent/WeKnora
versions:
- fixed: 0.2.5
vulnerable_at: 0.2.4
summary: WeKnora has Command Injection in MCP stdio test in github.com/Tencent/WeKnora
cves:
- CVE-2026-22688
ghsas:
- GHSA-78h3-63c4-5fqc
references:
- advisory: https://github.com/Tencent/WeKnora/security/advisories/GHSA-78h3-63c4-5fqc
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-22688
- fix: https://github.com/Tencent/WeKnora/commit/f7900a5e9a18c99d25cec9589ead9e4e59ce04bb
source:
id: GHSA-78h3-63c4-5fqc
created: 2026-01-12T11:47:25.214211787-05:00
review_status: UNREVIEWED