Wekan logo

Wekan

Open source kanban board application built with Meteor

Alternative to: trello


About Versions (307)

v11.28

2026-08-29

Binaries in these bundles

Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.

BundleBinaryFromVersionCheckedSHA256
amd64FerretDBwekan/FerretDBv1.63.0verifiedc9570b1b849d5066…
amd64Node.jsnodejs.orgv24.20.0verified2f2c0da162318f0d…
arm64FerretDBwekan/FerretDBv1.63.0verified019d60c6d2bcee74…
arm64Node.jsnodejs.orgv24.20.0verified5f4ddab610c1ab20…
armhfFerretDBwekan/FerretDBv1.63.0verifiedc1bad8f4e7f25f9b…
armhfNode.jswekan/node-patchesv24.20.0verifiedb8ed7065d44f0afe…
armv6FerretDBwekan/FerretDBv1.63.0verified136db594daa70e2c…
armv6Node.jswekan/node-patchesv24.20.0verifiedd5cefa6f8cc4acb1…
armv7FerretDBwekan/FerretDBv1.63.0verifiedc1bad8f4e7f25f9b…
armv7Node.jswekan/node-patchesv24.20.0verifiedc04c81e539347f39…
i386FerretDBwekan/FerretDBv1.63.0verified97053d14788ed4e3…
i386Node.jswekan/node-patchesv24.20.0verifiedbb44927307460dcf…
mac-arm64FerretDBwekan/FerretDBv1.63.0verifieda2b66ee8a97c8143…
mac-arm64Node.jsnodejs.orgv24.20.0verifiedb7bf7707070b950b…
mac-x64FerretDBwekan/FerretDBv1.63.0verified97d3963b4dc30ef9…
mac-x64Node.jsnodejs.orgv24.20.0verified26fc30891004603d…
ppc64leFerretDBwekan/FerretDBv1.63.0verifiedba5550302c335b1a…
ppc64leNode.jsnodejs.orgv24.20.0verified341307dcee20d883…
riscv64FerretDBwekan/FerretDBv1.63.0verified8041097ac56de1cd…
riscv64Node.jsunofficial-builds.nodejs.orgv24.20.0verifieda149c5bf85f98ff1…
s390xFerretDBwekan/FerretDBv1.63.0verified5cd8100052c464d9…
s390xNode.jsnodejs.orgv24.20.0verifiedca381121cb5a8d38…
win-arm64FerretDBwekan/FerretDBv1.63.0verifiedd931ecbc30b8aac5…
win-arm64Node.jsnodejs.orgv24.20.0verified31c6799744de8a54…
win64FerretDBwekan/FerretDBv1.63.0verified0439d99053a12151…
win64Node.jsnodejs.orgv24.20.0verified6cac9ffbca8f6a47…

A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.

v11.28 2026-08-29 WeKan ® release

In short: MailTitleBleed prevents stored board, list, card and other activity text from becoming active HTML in notification emails. The completed localized message is escaped at the final HTML boundary, and notification subjects cannot inject additional mail headers. CookieTokenBleed moves persistent resume authentication from JavaScript-readable cookies and Web Storage into Meteor’s native HttpOnly cookie flow.

PlatformBinaryFromVersionSHA256
amd64Node.jsnodejs.orgv24.19.014b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647
amd64FerretDBwekan/FerretDBv1.53.0eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d
arm64Node.jsnodejs.orgv24.19.001443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc
arm64FerretDBwekan/FerretDBv1.53.0bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da
mac-arm64Node.jsnodejs.orgv24.19.03f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94
mac-arm64FerretDBwekan/FerretDBv1.53.0cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e
mac-x64Node.jsnodejs.orgv24.19.0d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4
mac-x64FerretDBwekan/FerretDBv1.53.0d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3

This release fixes the following CRITICAL SECURITY ISSUES:

Notification activity text remains text in HTML email. Thanks to binary-lover and xet7.

GHSA-hp9m-vff5-7pvw, Moderate, CWE-79. Stored board, list and card titles and other activity values were interpolated into localized notification prose before that prose was used as an HTML email body. A writable member could therefore place active markup in a title and have it delivered to another member’s mail client.

The complete localized notification is now HTML-escaped once at the final output boundary, before its plain-text newlines become HTML line breaks. This protects every current and future activity parameter without changing ordinary text or the plain-text notification mode. The subject formatter also removes newlines so stored values cannot create additional mail headers. Positive and negative unit coverage exercises active markup, ordinary titles, header newlines, the final output wiring and all 246 locale bundles.

Persistent resume tokens are unavailable to browser scripts. Thanks to binary-lover and xet7.

CookieTokenBleed - GHSA-8phm-9rqm-v9hc, Moderate, CWE-1004. WeKan’s custom file-route authentication mirror wrote the Meteor resume token into a cookie from browser JavaScript, which cannot apply the HttpOnly attribute. Meteor also kept its original token in Local Storage, so script running in the WeKan origin could read either persistent copy.

WeKan now enables Meteor 3.5’s maintained HttpOnly resume-cookie flow on both client and server with persistent Web Storage disabled. The custom readable cookie synchronization and bootstrap code is removed, leaving only an in-memory credential in the active tab. Header login applies HttpOnly as well as SameSite=Lax and HTTPS Secure to the cookies it issues. Positive and negative regression coverage pins both configurations, the absence of browser cookie/token copying and retention of the Secure header-login path; existing request-auth and session-isolation suites remain green.

Thanks to above GitHub users for their contributions and translators for their translations.