CVE-2026-41455 Details
Description
WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL scheme field accepts any string without protocol restriction or destination validation. Attackers who can create or modify integrations can set webhook URLs to internal network addresses, causing the server to issue HTTP POST requests to attacker-controlled internal targets with full board event payloads, and can additionally exploit response handling to overwrite arbitrary comment text without authorization checks.
A server-side request forgery (SSRF) vulnerability has been identified in WeKan versions prior to 8.35. This vulnerability arises in the webhook integration URL handling, where the URL schema field allows any string without proper protocol restrictions or destination validations. Attackers with the ability to create or modify integrations can exploit this by setting webhook URLs to internal network addresses. This causes the server to send HTTP POST requests to attacker-controlled internal targets, including full board event payloads. Additionally, the vulnerability can be exploited by manipulating response handling to overwrite arbitrary comment text without authorization checks.
Users are advised to update to WeKan version 8.35 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 22, 2026CISA-ADP
Assessed Apr 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/wekan/wekan/commit/2cd702f48df2b8aef0e7381685f8e089986a18a4 | [email protected] | Source CodeVendor |
| https://github.com/wekan/wekan/releases/tag/v8.35 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/wekan-ssrf-via-webhook-url | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WeKan | < 8.35 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | New CVE Received | [email protected] |
Volerion