Hall of Fame
Back to Hall of Fame Contents Back to WeKan Website

HistoryScopeBleed

CVEIconVulnerability nameDate Responsible Security Disclosure byStarsProcessVulnerabilities
-

HistoryScopeBleed 2026-09-27 xet7 Gold starGold starGold star Found and fixed while integrating Scrum with universal History; current access and historical authorship were not consistently separated.

Universal History returned hidden cards to assigned-only members and could retain private-board history access after membership was removed. Its reversal path could also use an old board’s access to edit a card now on another board. Reads now enforce current scope before searching or counting; restore, undo and redo share current scope and card edit checks.

CWE-863. High severity. No CVE assigned. Fix prepared for the Upcoming release.

Details

Source fix and regression coverage

Detection

Routine history filtering is not an attack signal. A refused restoration may follow a legitimate concurrent reassignment or permission change, so this guard does not automatically classify those refusals as account-blocking attacks. Existing linked-card policy logging remains unchanged.

Verification

Positive and negative tests cover currently visible history, assigned-only cards, hidden search results and contributor counts, revoked private-board access, authorized restoration and denied edits to moved cards. Existing rule undo/redo and stale-state regressions also pass. Verification uses Chromium, Meteor and MongoDB; other browsers, FerretDB and Sandstorm were not exercised.

Audit and verification scope