Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL loading. During board import in Wekan, attachment URLs from user-supplied JSON data are fetched directly by the server without any URL validation or filtering, affecting both the Wekan and Trello import flows. The parseActivities() and parseActions() methods extract user-controlled attachment URLs, which are then passed directly to Attachments.load() for download with no sanitization. This Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to make the server issue arbitrary HTTP requests, potentially accessing internal network services such as cloud instance metadata endpoints (exposing IAM credentials), internal databases, and admin panels that are otherwise unreachable from outside the network. This issue has been fixed in version 8.34.
During board import in Wekan, attachment URLs are retrieved directly from JSON data provided by the user — both in the Wekan and Trello import flows. The parseActivities() and parseActions() methods extract user-controlled attachment URLs, which are then passed without any validation or filtering to the Attachments.load() function to fetch the resource. The absence of any URL sanitization allows an attacker to specify any target, including internal addresses inaccessible from outside the network.
An authenticated attacker can cause the server to execute HTTP requests to arbitrary resources, including internal databases, administrative panels, and cloud instance metadata endpoints (e.g., AWS IMDSv1), which may result in the theft of IAM credentials and compromise of infrastructure.
Wekan should be updated to version 8.34, in which the vulnerability has been fixed. The patch is available in the project's GitHub repository (commit 62216e36c15f55d4ef6cb97313db3aa54fc77fe0) and in release v8.34.
Wekan in versions 8.32 and 8.33
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XWekan Project Wekan
APPWekan Project8.328.33
Related vulnerabilities
Wekan IDOR: nieautoryzowana modyfikacja pól własnych na tablicach
Wekan: ujawnienie wrażliwych danych użytkowników przez publikację notificationUsers
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks pub...
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and rela...
WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not ...