PT-2026-23744 · Wekan+1 · Wekan
Ghsl
+1
·
Publicado
2026-03-06
·
Atualizado
2026-03-06
·
CVE-2026-30844
CVSS v4.0
9.3
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Wekan versions 8.32 through 8.33
Description
Wekan, an open-source kanban tool built with Meteor, has an issue where the server directly fetches attachment URLs during board import without proper validation or filtering. This affects both Wekan and Trello import flows. The
parseActivities() and parseActions() methods extract user-controlled attachment URLs and pass them to Attachments.load() for download without sanitization. This allows authenticated users to make arbitrary HTTP requests from the server, potentially accessing internal network services like cloud instance metadata endpoints (exposing IAM credentials), internal databases, and admin panels.Recommendations
Wekan versions 8.32 and 8.33 should be updated to version 8.34.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wekan