Path traversal in Wekan - #VU150007
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to write arbitrary files outside the attachment storage root.
The vulnerability exists due to path traversal in the Attachments collection namingFunction when processing attachment upload requests. A remote attacker can send a specially crafted upload request containing a traversal file identifier to write arbitrary content to an attacker-controlled path.