Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation by supplying a public URL that redirects to internal network addresses, allowing access to internal services and cloud metadata. | |
| Title | WeKnora before 0.7.0 SSRF via Unvalidated HTTP Redirects | |
| First Time appeared |
Tencent
Tencent weknora |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:tencent:weknora:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tencent
Tencent weknora |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T00:35:42.122Z
Reserved: 2026-09-14T23:08:34.530Z
Link: CVE-2026-91750
No data.
Status : Received
Published: 2026-09-15T01:16:54.630
Modified: 2026-09-15T01:16:54.630
Link: CVE-2026-91750
No data.
OpenCVE Enrichment
No data.
