GHSA-4mjm-vj9f-p629 was reported by crypto-nidh.
Current and CollectionFS-compatible avatar routes trusted the stored MIME type, allowing browser-executable content to be served under the WeKan origin.
Fix: a shared response policy converts HTML, XML, SVG and JavaScript MIME types to sandboxed opaque downloads with nosniff and frame denial. Safe image types remain inline. No Problems event is emitted because legitimate avatar views use this same path and cannot identify who supplied old metadata. Fixed for the upcoming WeKan v11.21 release on 2026-08-28.