| CVE | Vulnerability name | Date | Responsible Security Disclosure by | Vulnerabilities |
|---|---|---|---|---|
| GHSA-qf5c-63jx-mpv4 | CommentWriteBleed |
2026-08-22 |
Char0n1507 and
xet7
![]() Coordinated disclosure with a working reproduction and root-cause analysis. |
|
Single and bulk card creation and checklist creation used the comment capability, allowing Comment Only members to add board content outside their intended role.
Fix: all affected creation routes now require the canonical board write capability. Comment creation remains available through its separate comment permission.
| Timeline | Details |
|---|---|
| 2026-08-22 | Report received from Char0n1507 through GitHub Security Advisory GHSA-qf5c-63jx-mpv4. |
| 2026-08-22 | Fixed for the upcoming WeKan release. |