CVE-2025-11046: Tencent WeKnora test testEmbeddingModel server-side request forgery
A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. It is advisable to upgrade the affected component. The vendor responds: "We have confirmed that the issue mentioned in the report does not exist in the latest releases".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11046?
CVE-2025-11046 is classified as a critical vulnerability due to its potential for server-side request forgery.
How do I fix CVE-2025-11046?
To remediate CVE-2025-11046, you should update to the latest version of Tencent WeKnora that addresses this vulnerability.
Which software is affected by CVE-2025-11046?
CVE-2025-11046 affects Tencent WeKnora version 0.1.0.
What type of vulnerability is CVE-2025-11046?
CVE-2025-11046 is a server-side request forgery (SSRF) vulnerability.
Can CVE-2025-11046 be exploited remotely?
Yes, CVE-2025-11046 can be exploited remotely by manipulating the baseUrl argument.