Input validation error in Wekan - #VU140828
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information from internal services.
The vulnerability exists due to improper input validation in attachment URL validation and webhook delivery SSRF guard when processing user-supplied URLs. A remote user can supply a URL using an IPv6 transition address that embeds a private IPv4 destination to disclose sensitive information from internal services.
On affected deployments, the issue can expose responses from cloud metadata endpoints and other reachable RFC 1918, loopback, or link-local hosts.