Path traversal in Wekan - CVE-2026-52890
Published: July 28, 2026
Wekan
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in attachment file handling when processing attachment download requests using attacker-controlled versions.original.path and versions.original.storage metadata. A remote user can insert a specially crafted attachment record to disclose sensitive information.
The issue is reachable by a logged-in board member with write access and does not require user interaction.