Hall of Fame
Back to Hall of Fame Contents Back to WeKan Website

CopyIdentityBleed

CVEIconVulnerability nameDate Responsible Security Disclosure byStarsProcessVulnerabilities
-

CopyIdentityBleed 2026-09-29 xet7 Gold starGold starGold star Found and reproduced while reviewing TODO Later card-copy inputs; fixed by xet7.

Caller-controlled card-copy overrides could replace the source card identifier after its board membership check, causing private children from another card to be copied into a readable destination.

Copy overrides now accept only title and description text on a separate card object. Other fields are refused before sorting or copying children.

Board copying had the same fault: the copy method assigned caller-supplied properties, including the identifier, onto the source board, so a board admin could duplicate another private board. Board copies now accept only title, sort, type and card selection on a separate board object.

CWE-915. High severity. No CVE assigned. Fix prepared locally for the Upcoming release; not yet released.

Details

The local regression used two private boards owned by different test users. Replacing the copy source identifier copied the other board's checklist despite the caller lacking membership there. The defect is in application identity handling, not database filtering.

The supported override contract is optional string title and description. The source identity, board, methods and sort are preserved. Existing protected custom-field checks remain in place.

Detection

Extra-field override attempts are refused and summarized as CopyIdentityBleed in Admin Panel → Problems. Existing high-severity security policy blocks the attempting account. Supplied values and target identifiers are not logged. Malformed title/description values are rejected as input errors without attack records or account blocking.

Server destination validation and regression tests

Verification and remaining review

Positive and negative unit tests, a source-pattern scan, and real MongoDB/DDP/Chromium checks cover private child isolation, Problems attribution, source preservation and the copy dialog. Existing admin-only-field and Scrum copy regressions also run. Other browsers and database backends were not tested.

Server card copies now validate destination board, list and swimlane ownership before sorting or writing, rejecting missing or soft-deleted containers while preserving board-wide lists and archived-container copy behavior. Assigned-only child visibility, client-side template writes, direct Rules writes and concurrent permission changes remain separate review work. This is not a complete audit of every copy entry point.

Source fix and regression tests

Board copy

The board copy method merged every caller-supplied property onto the source board before copying, and the copy loads lists, cards and their children by that board's identifier. Passing another board's identifier duplicated a private board the caller was not a member of. Properties outside title, sort, type, without-cards and card selection are now refused and summarized as CopyIdentityBleed in Admin Panel → Problems; the REST copy route accepts only a string title. Unit, source-scan and Chromium regressions cover the refusal, the Problems record and malformed input.

Board copy fix and regression tests

Boundary review and verification scope