PT-2026-23620 · Weknora · Weknora

Aleister1102

·

Published

2026-03-05

·

Updated

2026-03-25

·

CVE-2026-30247

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WeKnora versions prior to 0.2.12
Description The application’s "Import document via URL" feature is susceptible to Server-Side Request Forgery (SSRF) through HTTP redirects. While the backend implements comprehensive URL validation, it fails to validate redirect targets. An attacker can bypass protections by using a redirect chain, forcing the server to access internal services. Docker-specific internal addresses like host.docker.internal are not blocked. The /api/v1/knowledge-bases/{id}/knowledge/url endpoint validates the initial URL but follows HTTP redirects without re-validating the destination. This allows attackers to submit a URL to an attacker-controlled domain, which responds with a 307 redirect to an internal service, enabling access to internal services and potential data exposure. The IsSSRFSafeURL() function validates the initial URL but does not validate HTTP redirect targets.
Recommendations Versions prior to 0.2.12 should be updated to version 0.2.12 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30247
GHSA-595M-WC8G-6QGC
GO-2026-4628
SUSE-SU-2026:1042-1

Affected Products

Weknora