| CVE | Vulnerability name | Date | Responsible Security Disclosure by | Vulnerabilities |
|---|---|---|---|---|
| GHSA-cp24-5m9m-wm97 | RoleBleed |
2026-08-22 |
senti-man and
xet7
![]() Coordinated disclosure with a working reproduction and root-cause analysis. |
|
Several checklist mutations required only read access, while comment creation required full write access and rejected legitimate Comment Only members.
Fix: content mutations now require board write access and comment creation uses the canonical comment capability. Regression tests cover allowed and denied roles.
| Timeline | Details |
|---|---|
| 2026-08-22 | Report received from senti-man through GitHub Security Advisory GHSA-cp24-5m9m-wm97. |
| 2026-08-22 | Fixed for the upcoming WeKan release. |