Authorization Bypass Through User-Controlled Key Affecting github.com/tencent/weknora/internal/application/repository package, versions <0.3.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMTENCENTWEKNORAINTERNALAPPLICATIONREPOSITORY-15470983
  • published12 Mar 2026
  • disclosed6 Mar 2026
  • creditLê Minh Quân

Introduced: 6 Mar 2026

CVE-2026-30857  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade github.com/Tencent/WeKnora/internal/application/repository to version 0.3.0 or higher.

Overview

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the GetKnowledgeBaseByID function. An attacker can access and duplicate sensitive data from other tenants by providing the identifier of a knowledge base belonging to a different tenant.

Note: This is only exploitable if the attacker is authenticated and knows or can guess the target knowledge base ID.

References

CVSS Base Scores

version 4.0
version 3.1