Skip to content

wekan

v9.23 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 13d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

docker javascript kanban meteor real-time sandstorm
+2 more
snapcraft wekan

ReleasePort's take

Moderate signal
editorial:auto 13d

WeKan v9.23 ships a critical security fix (BFLABleed) alongside filtering, minicard, and build process improvements. Operators should review release notes to assess applicability and deploy promptly.

Why it matters: Critical security fix for BFLABleed included; review release notes for affected versions and deploy immediately if your deployment is vulnerable.

Summary

AI summary

Updates https://github.com/wekan/wekan/commit/8baa9124a607e0620ab72d6d16871ed1c08e721a, https://github.com/wekan/wekan/commit/2cc30a85f21742f0f087a9846a52ee28e32830a5, and https://github.com/wekan/wekan/commit/fad217db8a55d95bd62d7d9c431cb60714a54d13 across a mixed release.

Changes in this release

Security Medium

Fixes critical security issue BFLABleed.

Fixes critical security issue BFLABleed.

Source: llm_adapter@2026-05-21

Confidence: low

Feature Medium

Adds local build cache for npm packages and http downloads.

Adds local build cache for npm packages and http downloads.

Source: llm_adapter@2026-05-21

Confidence: high

Feature Medium

Adds script to revert git add in build process.

Adds script to revert git add in build process.

Source: llm_adapter@2026-05-21

Confidence: high

Dependency Medium

Bumps brace-expansion from 5.0.5 to 5.0.6.

Bumps brace-expansion from 5.0.5 to 5.0.6.

Source: llm_adapter@2026-05-21

Confidence: low

Bugfix Medium

Fixes WeKan version update script issue.

Fixes WeKan version update script issue.

Source: llm_adapter@2026-05-21

Confidence: high

Bugfix Medium

Adds Filter test at part 4 and fixes related issues.

Adds Filter test at part 4 and fixes related issues.

Source: llm_adapter@2026-05-21

Confidence: low

Bugfix Medium

Fixes missing label and dates on minicards.

Fixes missing label and dates on minicards.

Source: llm_adapter@2026-05-21

Confidence: low

Bugfix Medium

Fixes Filter functionality issues.

Fixes Filter functionality issues.

Source: llm_adapter@2026-05-21

Confidence: low

Full changelog

This release fixes the following CRITICAL SECURITY ISSUES: https://wekan.fi/hall-of-fame/bflableed/ :

and adds the following new features:

and adds the following updates:

and fixes the following bugs:

Thanks to above GitHub users for their contributions and translators for their translations.

Security Fixes

  • Fix BFLABleed – critical security issue resolved (Hall of Fame entry)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track wekan

Get notified when new releases ship.

Sign up free

About wekan

The Open Source kanban, built with Meteor. GitHub issues/PRs are only for FLOSS Developers, not for support, support is at https://wekan.fi/commercial-support/ . New English strings for new features at imports/i18n/data/en.i18n.json . Non-English translations at https://app.transifex.com/wekan/wekan only.

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]