This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+2 more
Affected surfaces
ReleasePort's take
Moderate signalThe release fixes a critical security issue by moving Attachment Storage options to the Admin Panel and exposing Meteor user context to Express endpoints.
Why it matters: Addresses GHSA-g6vm-7757-pr88, a critical security flaw affecting attachment storage configuration and API authentication; immediate mitigation required for affected deployments.
Summary
AI summaryUpdates https://github.com/wekan/wekan/commit/8351bba818a04c9db11a0e3fa380a10f8d51482c, https://github.com/wekan/wekan/commit/8cda80752fd56c870cb139600fedc82643874c3b, and https://github.com/wekan/wekan/commit/c8430a8c1419cc68023ed918e26f7d4f279968ca across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes critical security issue GHSA-g6vm-7757-pr88 by moving Attachment Storage options to Admin Panel and exposing Meteor user context to Express endpoints. Fixes critical security issue GHSA-g6vm-7757-pr88 by moving Attachment Storage options to Admin Panel and exposing Meteor user context to Express endpoints. Source: llm_adapter@2026-05-27 Confidence: high |
— |
| Feature | Low |
Adds Header Login feature. Adds Header Login feature. Source: llm_adapter@2026-05-27 Confidence: high |
— |
| Feature | Low |
Updates platforms configuration. Updates platforms configuration. Source: llm_adapter@2026-05-27 Confidence: high |
— |
| Feature | Low |
Updates Windows installation documentation. Updates Windows installation documentation. Source: llm_adapter@2026-05-27 Confidence: high |
— |
| Feature | Low |
Upgrades Meteor runtime to 3.5‑beta.12. Upgrades Meteor runtime to 3.5‑beta.12. Source: llm_adapter@2026-05-27 Confidence: high |
— |
| Dependency | Low |
Bumps docker/login-action from 4.1.0 to 4.2.0. Bumps docker/login-action from 4.1.0 to 4.2.0. Source: llm_adapter@2026-05-27 Confidence: high |
— |
| Dependency | Low |
Bumps docker/metadata-action from 6.0.0 to 6.1.0. Bumps docker/metadata-action from 6.0.0 to 6.1.0. Source: llm_adapter@2026-05-27 Confidence: high |
— |
| Dependency | Low |
Bumps docker/build-push-action from 7.1.0 to 7.2.0. Bumps docker/build-push-action from 7.1.0 to 7.2.0. Source: llm_adapter@2026-05-27 Confidence: high |
— |
| Bugfix | Low |
Fixes typo. Fixes typo. Source: llm_adapter@2026-05-27 Confidence: high |
— |
Full changelog
This release fixes the following CRITICAL SECURITY ISSUES:
- Fix GHSA-g6vm-7757-pr88. Moved Attachment Storage options from board to Admin Panel. Changed API to use Expose Meteor user context to Express endpoints.
Thanks to Jan Kahmen of turingpoint GmbH for reporting GHSA-g6vm-7757-pr88 and xet7 for fixes and attachment improvements.
Thanks to nachocodoner about https://forums.meteor.com/t/expose-meteor-user-context-to-express-endpoints/64384.
and adds the following updates:
- Ubuntu 26.04 based core26 beta can be at devel like beta channel, not yet candidate.
Thanks to xet7. - Updated platforms.
Thanks to xet7. - Update Windows docs.
Thanks to xet7. - Bump docker/login-action from 4.1.0 to 4.2.0.
Thanks to dependabot. - Bump docker/metadata-action from 6.0.0 to 6.1.0.
Thanks to dependabot. - Bump docker/build-push-action from 7.1.0 to 7.2.0.
Thanks to dependabot. - Update dependencies and maintenance scripts
Part 1,
Part 2.
Thanks to developers of dependencies. - Add more tests. Fix tests.
Thanks to xet7. - Upgrade Meteor to 3.5-beta.12.
Thanks to harryadel.
and adds the following new features:
and fixes the following bugs:
- Fix typo.
Thanks to xet7.
Thanks to above GitHub users for their contributions and translators for their translations.
Security Fixes
- GHSA-g6vm-7757-pr88 – moved Attachment Storage options from board to Admin Panel and exposed Meteor user context to Express endpoints
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About wekan
The Open Source kanban, built with Meteor. GitHub issues/PRs are only for FLOSS Developers, not for support, support is at https://wekan.fi/commercial-support/ . New English strings for new features at imports/i18n/data/en.i18n.json . Non-English translations at https://app.transifex.com/wekan/wekan only.
Beta — feedback welcome: [email protected]