Executive brief
WeKan is an open-source kanban board application used for project management and collaboration. A security flaw in its webhook system allows users with integration permissions to force the server to send requests to internal network locations. This could lead to the exposure of sensitive internal data or the unauthorized modification of board comments, potentially disrupting business operations and compromising data integrity.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in WeKan's webhook integration component due to insufficient validation of the URL scheme and destination. An attacker with privileges to create or modify integrations (PR:L) can provide a malicious URL targeting internal network services. The server will subsequently issue HTTP POST requests containing board event payloads to these internal targets. Furthermore, a flaw in how the server handles responses from these webhooks allows an attacker to overwrite arbitrary comment text without proper authorization checks. This issue is resolved in version 8.35 by implementing protocol restrictions (allowing only HTTP/HTTPS) and blocking private/loopback addresses.
Affected products
- WeKan WeKan < 8.35
Timeline
- 2026-03-05: patched: Fixed in version 8.35 and commit 2cd702f48df2b8aef0e7381685f8e089986a18a4
- 2026-04-22: disclosed: Initial advisory publication