Skip to content
weknoraGHSA-595m-wc8g-6qgc

WeKnora is Vulnerable to SSRF via Redirection

Medium5.9CVE-2026-30247 · Published Mar 5, 2026 · updated Mar 23, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/Tencent/WeKnora
Go
< 0.2.120.2.12
Details and references

### Summary The application's "Import document via URL" feature is vulnerable to Server-Side Request Forgery (SSRF) through HTTP redirects. While the backend implements comprehensive URL validation (blocking private IPs, loopback addresses, reserved hostnames, and cloud metadata endpoints), it **fails to validate redirect targets**. An attacker can bypass all protections by using a redirect chain, forcing the server to access internal services. Additionally, Docker-specific internal addresses like `host.docker.internal` are not blocked. ### Details The `/api/v1/knowledge-bases/{id}/knowledge/url` endpoint validates the initial URL but follows HTTP redirects without re-validating the destination. This allows attackers to: 1. Submit a URL to an attacker-controlled domain (passes validation) 2. Have that domain respond with a 307 redirect to an internal service 3. The backend automatically follows the redirect without checking if the destination is restricted 4. The internal service response is exposed to the attacker ### Validation Gaps - The `IsSSRFSafeURL()` function (in `internal/utils/security.go`) validates the initial URL thoroughly, but there's no validation of HTTP redirect targets - `host.docker.internal` is not in the `restrictedHostnames` list - Docker-specific IP ranges (172.17.0.0/16 for bridge networks) are not explicitly blocked - The code validates `parsed.Hostname()` from the initial URL, but redirect Location headers bypass this check ### Root Cause Analysis The backend makes the security mistake of trusting the server's HTTP client library to be secure. In Go, when using http.Get() or similar functions, the standard library will automatically follow redirects up to 10 times by default. The SSRF validation only checks the URL passed to the endpoint, not intermediate redirects. ### PoC **Step 1**: Set up an attacker-controlled server that responds with a redirect: ```http HTTP/1.1 307 Temporary Redirect Location: http://host.docker.internal:7777 Content-Type: text/html Access-Control-Allow-Origin: * ``` **Step 2**: Send the request with a clean URL: ```http POST /api/v1/knowledge-bases/dbadd153-9e60-4213-9553-9f78dbcba0dc/knowledge/url HTTP/1.1 Host: localhost Content-Type: application/json Authorization: Bearer <valid_token> {"url":"https://attacker-domain.com","tag_id":""} ``` The URL `https://attacker-domain.com` passes all validation checks because: ✓ Valid `https://` scheme ✓ Not an IP address (it's a domain) ✓ Not in restricted hostnames ✓ Doesn't resolve to a private IP (assuming attacker controls a public domain) **Step 3**: The backend's HTTP client follows the redirect to `http://host.docker.internal:7777`, which: ✗ Is not validated ✗ `host.docker.internal` is not in the blocklist ✗ Successfully accesses the internal service ### Impact Vulnerability Type: Server-Side Request Forgery (SSRF) via HTTP Redirect **Who is Impacted**: - The organization running the application - Internal services and databases accessible from the application container - Services in the Docker network (other containers, internal infrastructure) - Sensitive data stored in internal services **Potential Consequences**: - Access to internal databases (PostgreSQL, MongoDB, MySQL) running in Docker - Information disclosure from internal services (Redis cache, configuration servers) - Access to Docker container metadata and environment variables - Lateral movement to other containers in the same Docker network - Exfiltration of sensitive configuration, API keys, or database credentials - Potential RCE if internal services have exploitable vulnerabilities

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2026-30247, GO-2026-4628

More weknora advisories

All
DateAdvisory
Mar 6WeKnora Vulnerable to Broken Access Control in Tenant Management
CVE-2026-30855Critical9.8fixed in 0.3.2
Mar 6WeKnora Vulnerable to Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection
CVE-2026-30856Medium5.4fixed in 0.3.0
Mar 6WeKnora has Unauthorized Cross‑Tenant Knowledge Base Cloning
CVE-2026-30857Medium5.9fixed in 0.3.0
Mar 6WeKnora has DNS Rebinding Vulnerability in web_fetch Tool that Allows SSRF to Internal Resources
CVE-2026-30858High7.5fixed in 0.3.0
Mar 6WeKnora has Broken Access Control - Cross-Tenant Data Exposure
CVE-2026-30859High7.5fixed in 0.2.12
Mar 6WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
CVE-2026-30860Critical10.0fixed in 0.2.12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.