| CVE | Vulnerability name | Date | Responsible Security Disclosure by | Vulnerabilities |
|---|---|---|---|---|
| GHSA-6jvj-85q3-6q2m | OwnerBleed |
2026-08-22 |
Char0n1507 and
xet7
![]() Coordinated disclosure with a working reproduction and root-cause analysis. |
|
The REST board-creation route copied owner and role fields from the request body instead of deriving ownership from the authenticated principal.
Fix: the authenticated caller is always the initial active administrator and owner. Client-supplied ownership and role flags are ignored.
| Timeline | Details |
|---|---|
| 2026-08-22 | Report received from Char0n1507 through GitHub Security Advisory GHSA-6jvj-85q3-6q2m. |
| 2026-08-22 | Fixed for the upcoming WeKan release. |