CVE-2026-30856
WeKnora Vulnerable to Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection in github.com/Tencent/WeKnora
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/Tencent/WeKnora/security/advisories/GHSA-67q9-58vj-32qx, https://forum.cursor.com/t/mcp-tools-name-collision-causing-cross-service-tool-call-failures/70946, https://modelcontextprotocol-security.io/ttps/tool-poisoning/tool-name-conflict, https://www.elastic.co/security-labs/mcp-tools-attack-defense-recommendations#tool-name-collision
