Server-Side Request Forgery in WeKan by WeKan Team
CVE-2026-41455
6.3MEDIUM
What is CVE-2026-41455?
A server-side request forgery vulnerability exists in WeKan due to improper validation in webhook integration URL handling. Specifically, the url schema field allows any string without protocol restrictions, enabling attackers with integration creation or modification abilities to set malicious webhook URLs pointing to internal network addresses. This could lead to unauthorized HTTP POST requests directed at attacker-controlled internal targets. Furthermore, the vulnerability may allow exploitation of response handling to overwrite arbitrary comment text without proper authorization checks.
Affected Version(s)
wekan 0 < 8.35.0
wekan 2cd702f48df2b8aef0e7381685f8e089986a18a4
