Executive brief
Kaneo is a project management and task collaboration platform. A flaw in its bulk task API allows authenticated workspace members with lower-privilege roles (viewer or member) to delete all tasks or modify task properties they should not have access to, causing permanent data loss or workflow disruption. An attacker need only be added to a workspace to execute this attack.
Technical details
The PATCH /api/task/bulk endpoint omits role-based permission checks (requireWorkspacePermission) that are enforced on all other task endpoints, verifying only workspace membership. Authenticated attackers with viewer or member roles can send bulk requests to delete tasks or modify status, priority, assignee, due date, and labels. Patch 2.12.2 adds the missing permission checks keyed to each operation (task:delete for delete, task:assign for assignee updates, etc.).
Affected products
- Kaneo Kaneo 2.3.12 to 2.12.1
Timeline
- 2026-09-21: disclosed
- 2026-08-04: patched: v2.12.2 released with fix