GitHub advisories GHSA-88mv-h439-rj8j and GHSA-9846-cj96-6hv5, reported by Char0n1507 and Reload3d.
Authenticated clients could search all email addresses and receive administrator, disabled-account, authentication-provider, organization and team metadata. Raw search input also became a database regular expression in two DDP paths.
Fix: the general publication now returns only public identity fields. Both paths escape search text as literal input and are rate-limited. These changes affect what legitimate responses carry and how ordinary punctuation is interpreted, so searches are not logged as attacks. Fixed in the upcoming WeKan release on 2026-08-25.