Server-Side Request Forgery in WeKan by WeKan Team
CVE-2026-41455

6.3MEDIUM

Key Information:

Vendor

Wekan

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-41455?

A server-side request forgery vulnerability exists in WeKan due to improper validation in webhook integration URL handling. Specifically, the url schema field allows any string without protocol restrictions, enabling attackers with integration creation or modification abilities to set malicious webhook URLs pointing to internal network addresses. This could lead to unauthorized HTTP POST requests directed at attacker-controlled internal targets. Furthermore, the vulnerability may allow exploitation of response handling to overwrite arbitrary comment text without proper authorization checks.

Affected Version(s)

wekan 0 < 8.35.0

wekan 2cd702f48df2b8aef0e7381685f8e089986a18a4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rodolphe GHIO
xet7
.