GHSA-5gcv-2hhj-7rg9 was reported by crypto-nidh.
A client with another user's global-search session ID could ask the pagination publications to rerun its stored selector and receive private card data without owning that session.
Fix: both publications now require authentication and load a session only by its owner and session ID together. Logged-out probes publish no cards and are bounded and summarized as SessionBleed in Admin Panel → Problems. Fixed in WeKan v11.16 on 2026-08-27.