Cross-site scripting in Wekan - #VU147310
Published: September 7, 2026 / Updated: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim\'s browser.
The vulnerability exists due to improper validation of active HTML attachments in Wekan attachment upload and download handling when an authenticated user uploads a crafted HTML attachment and a victim opens its full Meteor-Files URL. A remote user can upload an HTML attachment containing a crafted event handler to execute arbitrary JavaScript in a victim\'s browser.