PT-2025-32687 · Kanboard · Kanboard

Bryanqb07

·

Published

2025-08-12

·

Updated

2025-08-22

·

CVE-2025-55011

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Kanboard versions prior to 1.2.47
Description: Kanboard is project management software based on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API did not validate the task id parameter to ensure it was a valid task ID, nor did it check for path traversal. This allowed a malicious actor to write a file to any location on the system controlled by the application user. The impact is limited because the filename is hashed and has no extension.
Recommendations: Upgrade to version 1.2.47 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-55011
GHSA-26F4-RX96-XC55

Affected Products

Kanboard