Junglewise Threat Intelligence

CVE-2026-91750: Tencent WeKnora SSRF via unvalidated HTTP redirects

CVE-2026-91750 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Vendors: Tencent.

Executive brief

WeKnora is an open-source platform that processes raw documents for knowledge retrieval and reasoning. The system fails to validate where HTTP redirects lead when downloading documents from user-supplied URLs, allowing authenticated attackers to bypass security controls and access internal services and cloud metadata that should be blocked.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) flaw in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint. The vulnerable component fails to re-validate HTTP redirect targets after receiving a 3xx response when downloading documents from user-supplied URLs. An authenticated attacker can supply a public URL that initially passes SSRF validation, but redirects to internal network addresses (e.g., 127.0.0.1, private subnets) or cloud metadata endpoints (e.g., AWS IMDSv2). This allows attackers to access internal services and extract sensitive metadata despite initial validation. The issue affects WeKnora versions before 0.7.0; patches are available in 0.7.0 and later.

Affected products

  • Tencent WeKnora before 0.7.0

Timeline

  • 2026-09-15: disclosed: Published on NVD

References

Related threats