Wekan logo

Wekan

Open source kanban board application built with Meteor

Alternative to: trello


About Versions (307)

v11.41

2026-09-01

Binaries in these bundles

Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.

BundleBinaryFromVersionCheckedSHA256
amd64FerretDBwekan/FerretDBv1.65.0verified9835a47fce722f4b…
amd64Node.jsnodejs.orgv24.20.0verified2f2c0da162318f0d…
arm64FerretDBwekan/FerretDBv1.65.0verified49f64bbaeb436d4c…
arm64Node.jsnodejs.orgv24.20.0verified5f4ddab610c1ab20…
armhfFerretDBwekan/FerretDBv1.65.0verifiedc33acefab84439a3…
armhfNode.jswekan/node-patchesv24.20.0verifiedb8ed7065d44f0afe…
armv6FerretDBwekan/FerretDBv1.65.0verified185b48a2b514f742…
armv6Node.jswekan/node-patchesv24.20.0verifiedd5cefa6f8cc4acb1…
armv7FerretDBwekan/FerretDBv1.65.0verifiedc33acefab84439a3…
armv7Node.jswekan/node-patchesv24.20.0verifiedc04c81e539347f39…
i386FerretDBwekan/FerretDBv1.65.0verified2fc3cdcb05633d5a…
i386Node.jswekan/node-patchesv24.20.0verifiedbb44927307460dcf…
mac-arm64FerretDBwekan/FerretDBv1.65.0verifiedc0f1f3e134e363ce…
mac-arm64Node.jsnodejs.orgv24.20.0verifiedb7bf7707070b950b…
mac-x64FerretDBwekan/FerretDBv1.65.0verified415587e812b4749e…
mac-x64Node.jsnodejs.orgv24.20.0verified26fc30891004603d…
ppc64leFerretDBwekan/FerretDBv1.65.0verified42bc7b642949f3e7…
ppc64leNode.jsnodejs.orgv24.20.0verified341307dcee20d883…
riscv64FerretDBwekan/FerretDBv1.65.0verified0f59bc510eb30831…
riscv64Node.jsunofficial-builds.nodejs.orgv24.20.0verifieda149c5bf85f98ff1…
s390xFerretDBwekan/FerretDBv1.65.0verified30e9cbb634f95689…
s390xNode.jsnodejs.orgv24.20.0verifiedca381121cb5a8d38…
win-arm64FerretDBwekan/FerretDBv1.65.0verified1583f1c1f4a01851…
win-arm64Node.jsnodejs.orgv24.20.0verified31c6799744de8a54…
win64FerretDBwekan/FerretDBv1.65.0verified2c29f1d495936048…
win64Node.jsnodejs.orgv24.20.0verified6cac9ffbca8f6a47…

A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.

v11.41 2026-09-01 WeKan ® release

In short: MimeBleed attachment defenses now reject an additional stored XSS syntax and fail closed on every storage backend, including legacy records with executable metadata. All Boards sorting now changes immediately and persists reliably, while FerretDB avoids a multi-gigabyte allocation that could cause high CPU, connection resets and database crashes. Multi-user browser coverage also keeps simultaneous sessions genuinely independent.

PlatformBinaryFromVersionSHA256
amd64Node.jsnodejs.orgv24.19.014b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647
amd64FerretDBwekan/FerretDBv1.53.0eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d
arm64Node.jsnodejs.orgv24.19.001443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc
arm64FerretDBwekan/FerretDBv1.53.0bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da
mac-arm64Node.jsnodejs.orgv24.19.03f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94
mac-arm64FerretDBwekan/FerretDBv1.53.0cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e
mac-x64Node.jsnodejs.orgv24.19.0d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4
mac-x64FerretDBwekan/FerretDBv1.53.0d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3

This release fixes the following CRITICAL SECURITY ISSUE of MimeBleed:

Attachment content is fail-closed on every storage path. Thanks to avrlab233 and xet7.

Slash-separated tags with unquoted event handlers could bypass the markup sniff, filesystem-destination uploads skipped the validation applied during storage migration, and Meteor-Files could serve executable stored metadata inline from its original route. Upload validation now recognizes those handler and JavaScript-URI forms for every destination. Filesystem, GridFS and cloud downloads share one response policy that forces HTML, SVG, XML and JavaScript types or filenames to an opaque attachment with nosniff, frame denial and a sandboxed CSP. Rejected uploads remain visible as MimeBleed events in Admin Panel → Problems; ordinary file views are transformed safely rather than logged because the response path cannot distinguish an attack from a legitimate view. Mocha covers the reported payload and negative samples, Node coverage pins all storage shapes, and Chromium, Firefox and WebKit exercise the full download route.

and fixes the following bugs:

All Boards - sorting uses one reactive choice from the popup through the rendered board grid.

The chosen board order takes effect immediately and remains selected. Thanks to jullbo and xet7.

The profile was updated on the server, but the popup, pagination and board grid continued reading a current-user document that was not guaranteed to be republished after the click. The chosen mode now has an immediate reactive client value, is shared by every sorting consumer, and rolls back if persistence fails. Browser coverage verifies both visible A→Z ordering and the stored profile choice, including the selected state when the popup is reopened.

FerretDB - sorted queries allocate memory for real results instead of a wire-protocol sentinel limit.

Effectively unlimited sorted queries no longer reserve gigabytes up front. Thanks to jeremy-arsia, Heart1010 and xet7.

A client’s ordinary sorted find can express no practical limit as 2147483647. FerretDB used that number as a Go slice’s initial capacity and could immediately request about 16 GiB, causing high CPU, out-of-memory crashes, connection resets and temporarily missing boards while the database restarted. The bounded top-k heap now starts small and grows only for documents that exist. A maximum-limit regression test verifies correct ordering without the eager allocation, while the finite-limit test keeps the bounded behavior covered.

and improves developer tooling:

Simultaneous browser users keep independent sessions. Thanks to xet7.

The multi-user stability test opened both users in one browser context, where Meteor’s origin-scoped resume token necessarily made the second login replace the first. It now uses a separate context per user, matching real independent sessions and removing the false timeout while still verifying both board views.

Thanks to above GitHub users for their contributions and translators for their translations.