Security: wekan/wekan
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
allowPrivateOnly setting: DDP denies public board create, method stores publicGHSA-9qg3-jfch-jwqv published
Sep 14, 2026 by xet7Moderate -
Non-admin sendInvitation accepts an arbitrary private boardId (mail confirmed; redeem blocked in harness)GHSA-p9qq-frc9-qfhm published
Sep 14, 2026 by xet7Moderate -
Linked-card share lets comment-only members write the source cardGHSA-jp39-3pf7-q5ww published
Sep 14, 2026 by xet7Moderate -
Removed members re-add themselves via acceptInvite after a documented-allowed profile readGHSA-h2g5-h8g8-grxf published
Sep 14, 2026 by xet7High -
REST board title update allows normal members; DDP/admin siblings denyGHSA-v368-jwmq-53h8 published
Sep 14, 2026 by xet7Moderate -
moveList lets comment-only members clone/archive lists (REST/DDP siblings deny)GHSA-8g7j-c3xh-36h7 published
Sep 14, 2026 by xet7Moderate -
Button rules let comment-only members mutate private-board cardsGHSA-7c42-4mc2-99g2 published
Sep 14, 2026 by xet7Moderate -
Comment create stores arbitrary cardId, leaking private-board cards over PubSubGHSA-47xv-5hh2-x5c9 published
Sep 14, 2026 by xet7Moderate -
Cross-board disclosure via unvalidated subtasksDefaultBoardIdGHSA-483r-px2x-cjcg published
Sep 14, 2026 by xet7High -
Avatars Collection Lacks `protected` Callback — Library-Native Download URL Bypasses Avatar Visibility AuthorizationGHSA-6h68-m988-228w published
Sep 9, 2026 by xet7Moderate