Server-Side Request Forgery (SSRF) in Wekan - #VU140827
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information from internal resources.
The vulnerability exists due to server-side request forgery in the live Trello import download path when processing attacker-controlled attachment URLs that redirect after validation. A remote user can supply a public URL that redirects to an internal address to disclose sensitive information from internal resources.
The issue is non-blind because the fetched response body is stored as an imported attachment and can be read back through Wekan.