GHSA-xwv8-m73h-68vg was reported by crypto-nidh.
An administrator-configured OIDC claim whitelist could copy attacker-controlled access-token claims over the trusted userinfo id, username, email and other service-owned fields, potentially linking the attacker's login to a victim account.
Fix: whitelisted claims can add only non-reserved metadata. Identity, token, group and object-prototype fields remain owned by WeKan and trusted userinfo. No Problems event is emitted because legitimate OIDC logins use the same path. Fixed in the upcoming WeKan release on 2026-08-26.