Executive brief
Wekan is an open-source Kanban board application used for project management and collaboration. A vulnerability in the way the system handles file attachments allows a logged-in user to bypass security checks and access sensitive files on the server's hard drive. This could lead to the theft of database credentials and other configuration secrets, or allow an attacker to crash the service entirely, disrupting business operations.
Technical details
A path traversal vulnerability exists in Wekan's attachment handling prior to version 9.31. While the application implemented a check to prevent path traversal during file updates, it failed to apply similar logic to the initial insertion via the '/attachments/insert' DDP method. An authenticated board member can provide a crafted document containing absolute filesystem paths in the 'versions.original.path' field. Because 'FileStoreStrategyFilesystem.getReadStream()' lacks a storage-root containment check, it will stream any file accessible to the application process. Attackers can exploit this to read sensitive environment variables (like MONGO_URL) or cause a denial of service by requesting special system files like '/dev/zero', which exhausts memory during the buffering process.
Affected products
- Wekan Wekan < 9.31
Timeline
- 2026-05-27: patched: Fix included in release v9.31
- 2026-05-30: advisory: GitHub Security Advisory GHSA-g6vm-7757-pr88 published
- 2026-07-15: disclosed: CVE-2026-52890 published to NVD