CVE-2026-30856 describes a medium-severity vulnerability in WeKnora, an LLM-powered framework, prior to version 0.3.0. This flaw, categorized as a tool name collision and indirect prompt injection, allows a malicious remote MCP server to hijack tool execution. Attackers can exploit ambiguous naming conventions to register malicious tools, overwriting legitimate ones and redirecting LLM execution to exfiltrate sensitive data or execute other tools with user privileges. The CVSS score is 5.9 (MEDIUM), indicating a network-based attack with high attack complexity, requiring low privileges and user interaction, leading to high confidentiality impact and low integrity/availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.0CPE matchmatch criteria | cpe:2.3:a:tencent:weknora:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.