WeKnora is Vulnerable to SSRF via Redirection
Medium5.9CVE-2026-30247 · Published Mar 5, 2026 · updated Mar 23, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/Tencent/WeKnora Go | < 0.2.12 | 0.2.12 |
Details and references
### Summary The application's "Import document via URL" feature is vulnerable to Server-Side Request Forgery (SSRF) through HTTP redirects. While the backend implements comprehensive URL validation (blocking private IPs, loopback addresses, reserved hostnames, and cloud metadata endpoints), it **fails to validate redirect targets**. An attacker can bypass all protections by using a redirect chain, forcing the server to access internal services. Additionally, Docker-specific internal addresses like `host.docker.internal` are not blocked. ### Details The `/api/v1/knowledge-bases/{id}/knowledge/url` endpoint validates the initial URL but follows HTTP redirects without re-validating the destination. This allows attackers to: 1. Submit a URL to an attacker-controlled domain (passes validation) 2. Have that domain respond with a 307 redirect to an internal service 3. The backend automatically follows the redirect without checking if the destination is restricted 4. The internal service response is exposed to the attacker ### Validation Gaps - The `IsSSRFSafeURL()` function (in `internal/utils/security.go`) validates the initial URL thoroughly, but there's no validation of HTTP redirect targets - `host.docker.internal` is not in the `restrictedHostnames` list - Docker-specific IP ranges (172.17.0.0/16 for bridge networks) are not explicitly blocked - The code validates `parsed.Hostname()` from the initial URL, but redirect Location headers bypass this check ### Root Cause Analysis The backend makes the security mistake of trusting the server's HTTP client library to be secure. In Go, when using http.Get() or similar functions, the standard library will automatically follow redirects up to 10 times by default. The SSRF validation only checks the URL passed to the endpoint, not intermediate redirects. ### PoC **Step 1**: Set up an attacker-controlled server that responds with a redirect: ```http HTTP/1.1 307 Temporary Redirect Location: http://host.docker.internal:7777 Content-Type: text/html Access-Control-Allow-Origin: * ``` **Step 2**: Send the request with a clean URL: ```http POST /api/v1/knowledge-bases/dbadd153-9e60-4213-9553-9f78dbcba0dc/knowledge/url HTTP/1.1 Host: localhost Content-Type: application/json Authorization: Bearer <valid_token> {"url":"https://attacker-domain.com","tag_id":""} ``` The URL `https://attacker-domain.com` passes all validation checks because: ✓ Valid `https://` scheme ✓ Not an IP address (it's a domain) ✓ Not in restricted hostnames ✓ Doesn't resolve to a private IP (assuming attacker controls a public domain) **Step 3**: The backend's HTTP client follows the redirect to `http://host.docker.internal:7777`, which: ✗ Is not validated ✗ `host.docker.internal` is not in the blocklist ✗ Successfully accesses the internal service ### Impact Vulnerability Type: Server-Side Request Forgery (SSRF) via HTTP Redirect **Who is Impacted**: - The organization running the application - Internal services and databases accessible from the application container - Services in the Docker network (other containers, internal infrastructure) - Sensitive data stored in internal services **Potential Consequences**: - Access to internal databases (PostgreSQL, MongoDB, MySQL) running in Docker - Information disclosure from internal services (Redis cache, configuration servers) - Access to Docker container metadata and environment variables - Lateral movement to other containers in the same Docker network - Exfiltration of sensitive configuration, API keys, or database credentials - Potential RCE if internal services have exploitable vulnerabilities
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-918
- Also known as
- CVE-2026-30247, GO-2026-4628
More weknora advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 6 | WeKnora Vulnerable to Broken Access Control in Tenant Management CVE-2026-30855Critical9.8fixed in 0.3.2 | Critical9.8 | 0.3.2 |
| Mar 6 | WeKnora Vulnerable to Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection CVE-2026-30856Medium5.4fixed in 0.3.0 | Medium5.4 | 0.3.0 |
| Mar 6 | WeKnora has Unauthorized Cross‑Tenant Knowledge Base Cloning CVE-2026-30857Medium5.9fixed in 0.3.0 | Medium5.9 | 0.3.0 |
| Mar 6 | WeKnora has DNS Rebinding Vulnerability in web_fetch Tool that Allows SSRF to Internal Resources CVE-2026-30858High7.5fixed in 0.3.0 | High7.5 | 0.3.0 |
| Mar 6 | WeKnora has Broken Access Control - Cross-Tenant Data Exposure CVE-2026-30859High7.5fixed in 0.2.12 | High7.5 | 0.2.12 |
| Mar 6 | WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query Tool CVE-2026-30860Critical10.0fixed in 0.2.12 | Critical10.0 | 0.2.12 |