PT-2026-23744 · Wekan+1 · Wekan

Ghsl

+1

·

Publicado

2026-03-06

·

Atualizado

2026-03-06

·

CVE-2026-30844

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Wekan versions 8.32 through 8.33
Description Wekan, an open-source kanban tool built with Meteor, has an issue where the server directly fetches attachment URLs during board import without proper validation or filtering. This affects both Wekan and Trello import flows. The parseActivities() and parseActions() methods extract user-controlled attachment URLs and pass them to Attachments.load() for download without sanitization. This allows authenticated users to make arbitrary HTTP requests from the server, potentially accessing internal network services like cloud instance metadata endpoints (exposing IAM credentials), internal databases, and admin panels.
Recommendations Wekan versions 8.32 and 8.33 should be updated to version 8.34.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30844

Produtos afetados

Wekan