CVE-2026-30860: WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
(updated )
A critical Remote Code Execution (RCE) vulnerability exists in the application’s database query functionality. The validation system fails to recursively inspect child nodes within PostgreSQL array expressions and row expressions, allowing attackers to bypass SQL injection protections. By smuggling dangerous PostgreSQL functions inside these expressions and chaining them with large object operations and library loading capabilities, an unauthenticated attacker can achieve arbitrary code execution on the database server with database user privileges.
<strong>Impact:</strong> Complete system compromise with arbitrary code execution
References
Code Behaviors & Features
Detect and mitigate CVE-2026-30860 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →