Skip to content

wekan

v9.52 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

docker javascript kanban meteor real-time sandstorm
+2 more
snapcraft wekan

Affected surfaces

auth

Summary

AI summary

Fixed critical XSS vulnerability InputBleed in card dependency import.

Full changelog

v9.52 2026-06-18 WeKan ® release

This release fixes the following CRITICAL SECURITY ISSUE of InputBleed:

  • Fixed InputBleed:
    incomplete multi-character HTML sanitization in card dependency
    import allowed HTML/script element injection](https://github.com/wekan/wekan/blob/main/client/lib/importDependencies.js)
    (CWE-79 Cross-site Scripting, CWE-80 Improper Neutralization of Script-Related HTML
    Tags, CWE-116 Improper Encoding or Escaping of Output; GitHub CodeQL code scanning
    alert #421, rule js/incomplete-multi-character-sanitization, severity High).
    stripHtml() in client/lib/importDependencies.js removed HTML tags with a single
    pass of /<[^>]*>/g. That is an incomplete multi-character sanitization in two ways:
    removing one match can splice surrounding text into a new match (so the replacement
    must be looped to a fixed point), and a dangling, unclosed tag that has no closing
    > (for example a trailing <script or <svg/onload=...) is never matched by the
    regex at all and survives untouched — leaving <script in the output, exactly as the
    scanner warned. A crafted card-dependency ("Red Strings") import file (the
    WeKan/generic JSON or Miro item titles and connector captions that pass through
    stripHtml) could therefore smuggle an HTML/script fragment past the sanitizer.
    Fixed by looping the tag-stripping replacement to a fixed point and then removing any
    remaining stray </> characters, so neither a complete nor a partial tag can
    remain.
    Thanks to GitHub CodeQL, xet7 and Claude.

and fixes the following bugs:

  • Card Details popup:
    removed the redundant empty second popup that appeared at
    the top of the page when a card was opened as a popup (for example from the
    Board Table view Edit link or from search results). The card details content is
    always position:fixed, so it renders as its own framed box and escapes the
    generic popup wrapper, leaving that wrapper (with its "Card Details" title
    header, border and background) visible as an empty box. The wrapper is now
    collapsed and made invisible so only the card itself shows. The card's own close
    button now closes the popup (in addition to clicking outside or pressing Escape).
    Thanks to xet7.

Thanks to above GitHub users for their contributions and translators for their translations.

Security Fixes

  • CVE-2026-XXXXX — InputBleed: incomplete multi-character HTML sanitization in card dependency import allowed XSS (CWE-79, CWE-80, CWE-116)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track wekan

Get notified when new releases ship.

Sign up free

About wekan

The Open Source kanban, built with Meteor. GitHub issues/PRs are only for FLOSS Developers, not for support, support is at https://wekan.fi/commercial-support/ . New English strings for new features at imports/i18n/data/en.i18n.json . Non-English translations at https://app.transifex.com/wekan/wekan only.

All releases →

Related context

Beta — feedback welcome: [email protected]