GHSA-c3ch-34g5-x3x7 was reported by Char0n1507.
A logged-out DDP client could request known usernames and receive profile, authentication-provider, activity, organization, team and imported-username metadata.
Fix: the mini-profile publication now completes without data unless the connection has an authenticated user. Denied attempts are bounded and summarized as MiniProfileBleed in Admin Panel → Problems with their source address. Fixed in the upcoming WeKan release on 2026-08-25.