SSRF Vulnerability in WeKnora Software by Tencent
CVE-2026-91750
7.1HIGH
What is CVE-2026-91750?
WeKnora version prior to 0.7.0 is vulnerable to SSRF attacks due to a failure to properly re-validate HTTP redirect targets within the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint. This flaw allows authenticated attackers to bypass the initial SSRF validation by providing a public URL that redirects to internal network addresses. As a result, attackers can gain unauthorized access to internal services and cloud metadata, potentially leading to further exploitation of the system.
Affected Version(s)
WeKnora 0.5.2 < 0.7.0
