Wekan Server-Side Request Forgery Vulnerability via Webhook Integration URLs

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Wekan, an open-source kanban application built with Meteor. This vulnerability exists in versions prior to 9.32. The issue arises because webhook integration URLs are stored from user input without proper validation. These URLs are later fetched by the server, allowing an attacker to send requests to internal services or metadata endpoints. The vulnerability affects board administrators who can configure malicious webhook URLs that trigger server-side requests to private or internal resources.

Impact

Exploitation of this vulnerability allows an authenticated user with board admin privileges to access internal services, scan network resources, interact with private APIs or databases, and exfiltrate data via webhook POST payloads to internal endpoints.

Remediation

Users can update to Wekan version 9.32 or later, where this vulnerability has been fixed. Instructions for downloading the latest version are available on the Wekan GitHub Releases page.

Added: Jul 15, 2026, 10:30 PM
Updated: Jul 15, 2026, 10:30 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.5
remediation
7.7
relevance
9.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.