Hall of Fame trophy
Back to Hall of Fame Contents

Contents / SearchBleed

Global-search selector injection and authorization bypass

GHSA-33h9-rc5h-667p was reported by crypto-nidh.

The global-search publication accepted a database selector from an authenticated client and used it instead of its normal board-scoped query. On MongoDB this could execute database operators, cause denial of service and expose an oracle over cards on inaccessible boards. Stored selectors could also be replayed by the pagination publications.

Fix: executable selectors are rejected through WeKan's shared NoSQL guard, while other selectors are conjoined with the caller's current authorized board IDs. The shared database path repeats both checks before initial or stored pagination selectors execute, protecting sessions created by older releases after upgrade. Fixed for the upcoming WeKan release on 2026-08-29.