GHSA-xcxp-hx9w-q5q9 was reported by crypto-nidh.
The CollectionFS-compatible attachment route protected SVG files but served other browser-executable MIME types without the same CSP, nosniff and frame restrictions.
Fix: HTML, XML, SVG and JavaScript types now share one sandboxed opaque-download policy. No Problems event is emitted because legitimate legacy downloads use the same path and cannot attribute dangerous old metadata to the current viewer. Fixed for the upcoming WeKan v11.21 release on 2026-08-28.