CVE-2026-30861 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-30861 requires immediate attention.
· 3 min read
```htmlExecutive Summary
A critical unauthenticated remote code execution (RCE) vulnerability, CVE-2026-30861, has been discovered in the MCP stdio configuration of the github.com/Tencent/WeKnora application, affecting versions 2.0.5 to 2.0.9. This flaw allows attackers to register accounts without restrictions and execute arbitrary commands on the server. Immediate action is required to mitigate potential exploitation.
Immediate Action
- Upgrade to version
2.0.10or later immediately. - Review logs for any suspicious activity since version
2.0.5. - Check for unauthorized MCP configurations that could be exploited.
- Monitor for any unauthorized file creation or modifications.
- Assume breach if any signs of compromise are found.
- Link to vendor advisories (placeholder for future updates).
Affected Versions
2.0.5vulnerable; upgrade to2.0.10+2.0.6vulnerable; upgrade to2.0.10+2.0.7vulnerable; upgrade to2.0.10+2.0.8vulnerable; upgrade to2.0.10+2.0.9vulnerable; upgrade to2.0.10+
Resolution Guide
To upgrade to the patched version, use the following commands:
npm install github.com/Tencent/WeKnora@2.0.10
For additional hardening, consider disabling the MCP stdio feature if not in use:
config.mcp_stdio_enabled = false
Example of a minimal patch snippet to block the -p flag:
if args.includes('-p') { throw new Error('Invalid argument: -p is not allowed.'); }
Detection & Verification
To check if your application is vulnerable, verify the installed version:
npm list github.com/Tencent/WeKnora
To ensure the fix is applied, confirm the version is 2.0.10 or later:
npm list github.com/Tencent/WeKnora
Risk and Impact
The vulnerability allows unauthenticated attackers to execute arbitrary commands on the server, leading to complete system compromise. This could result in data breaches, installation of malware, and lateral movement within internal systems, affecting not just the application but potentially exposing sensitive information across the network.
```