GHSA-5r3j-h65h-fg22 was reported by crypto-nidh.
A logged-out DDP client could query a known id, email or username and receive that account's authentication method, teams and organizations.
Fix: the publication now completes without querying unless the connection is authenticated. Denied attempts are bounded and summarized as MembershipBleed in Admin Panel → Problems with their source address. Fixed in the upcoming WeKan release on 2026-08-26.