Input validation error in Wekan - #VU147311
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose ordinary request metadata.
The vulnerability exists due to improper input validation in the XLSX attachment preview when rendering an uploaded XLSX file with a crafted sheet tab color. A remote user can upload a specially crafted XLSX attachment to inject CSS declarations into a sheet-tab button.
An authorized board member must open the attachment preview.