Hall of Fame
Back to Hall of Fame Contents Back to WeKan Website

ExportScopeBleed

CVEIconVulnerability nameDate Responsible Security Disclosure byStarsProcessVulnerabilities
-

ExportScopeBleed 2026-09-27 xet7 Gold starGold starGold star Found and fixed while reviewing native Scrum export permissions; board visibility did not enforce assigned-only card access.

Board-wide exporters accepted private-board visibility for assigned-only members while reading unassigned cards and related data. All nine exporter authorization methods now share an assignment-aware decision. Unfiltered exports are refused for assigned-only members; explicitly scoped Scrum reports retain access.

CWE-863. High severity. No CVE assigned. Fix prepared for the Upcoming release.

Details

Source fix and regression coverage

Source audit, fix and verification scope

Detection

Ordinary export menus can lead assigned-only users to unsupported exports. A refusal alone cannot identify an attack, so no new account-blocking canary is added. Existing generic export-denial logging remains.

Verification

Policy tests cover all assigned-only roles and preserve ordinary member access and scoped Scrum charts. A source regression covers all nine exporter authorization methods; HTTP tests cover native JSON, ZIP, CSV, calendar, PDF, Excel and chart formats. Local verification uses Chromium, Meteor and MongoDB; other browsers, FerretDB and Sandstorm were not exercised.