Wekan
Open source kanban board application built with Meteor
Alternative to: trello
v11.41
2026-09-01Binaries in these bundles
Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.
| Bundle | Binary | From | Version | Checked | SHA256 |
|---|---|---|---|---|---|
| amd64 | FerretDB | wekan/FerretDB | v1.65.0 | verified | 9835a47fce722f4b… |
| amd64 | Node.js | nodejs.org | v24.20.0 | verified | 2f2c0da162318f0d… |
| arm64 | FerretDB | wekan/FerretDB | v1.65.0 | verified | 49f64bbaeb436d4c… |
| arm64 | Node.js | nodejs.org | v24.20.0 | verified | 5f4ddab610c1ab20… |
| armhf | FerretDB | wekan/FerretDB | v1.65.0 | verified | c33acefab84439a3… |
| armhf | Node.js | wekan/node-patches | v24.20.0 | verified | b8ed7065d44f0afe… |
| armv6 | FerretDB | wekan/FerretDB | v1.65.0 | verified | 185b48a2b514f742… |
| armv6 | Node.js | wekan/node-patches | v24.20.0 | verified | d5cefa6f8cc4acb1… |
| armv7 | FerretDB | wekan/FerretDB | v1.65.0 | verified | c33acefab84439a3… |
| armv7 | Node.js | wekan/node-patches | v24.20.0 | verified | c04c81e539347f39… |
| i386 | FerretDB | wekan/FerretDB | v1.65.0 | verified | 2fc3cdcb05633d5a… |
| i386 | Node.js | wekan/node-patches | v24.20.0 | verified | bb44927307460dcf… |
| mac-arm64 | FerretDB | wekan/FerretDB | v1.65.0 | verified | c0f1f3e134e363ce… |
| mac-arm64 | Node.js | nodejs.org | v24.20.0 | verified | b7bf7707070b950b… |
| mac-x64 | FerretDB | wekan/FerretDB | v1.65.0 | verified | 415587e812b4749e… |
| mac-x64 | Node.js | nodejs.org | v24.20.0 | verified | 26fc30891004603d… |
| ppc64le | FerretDB | wekan/FerretDB | v1.65.0 | verified | 42bc7b642949f3e7… |
| ppc64le | Node.js | nodejs.org | v24.20.0 | verified | 341307dcee20d883… |
| riscv64 | FerretDB | wekan/FerretDB | v1.65.0 | verified | 0f59bc510eb30831… |
| riscv64 | Node.js | unofficial-builds.nodejs.org | v24.20.0 | verified | a149c5bf85f98ff1… |
| s390x | FerretDB | wekan/FerretDB | v1.65.0 | verified | 30e9cbb634f95689… |
| s390x | Node.js | nodejs.org | v24.20.0 | verified | ca381121cb5a8d38… |
| win-arm64 | FerretDB | wekan/FerretDB | v1.65.0 | verified | 1583f1c1f4a01851… |
| win-arm64 | Node.js | nodejs.org | v24.20.0 | verified | 31c6799744de8a54… |
| win64 | FerretDB | wekan/FerretDB | v1.65.0 | verified | 2c29f1d495936048… |
| win64 | Node.js | nodejs.org | v24.20.0 | verified | 6cac9ffbca8f6a47… |
A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.
v11.41 2026-09-01 WeKan ® release
In short: MimeBleed attachment defenses now reject an additional stored XSS syntax and fail closed on every storage backend, including legacy records with executable metadata. All Boards sorting now changes immediately and persists reliably, while FerretDB avoids a multi-gigabyte allocation that could cause high CPU, connection resets and database crashes. Multi-user browser coverage also keeps simultaneous sessions genuinely independent.
| Platform | Binary | From | Version | SHA256 |
|---|---|---|---|---|
| amd64 | Node.js | nodejs.org | v24.19.0 | 14b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647 |
| amd64 | FerretDB | wekan/FerretDB | v1.53.0 | eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d |
| arm64 | Node.js | nodejs.org | v24.19.0 | 01443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc |
| arm64 | FerretDB | wekan/FerretDB | v1.53.0 | bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da |
| mac-arm64 | Node.js | nodejs.org | v24.19.0 | 3f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94 |
| mac-arm64 | FerretDB | wekan/FerretDB | v1.53.0 | cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e |
| mac-x64 | Node.js | nodejs.org | v24.19.0 | d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4 |
| mac-x64 | FerretDB | wekan/FerretDB | v1.53.0 | d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3 |
This release fixes the following CRITICAL SECURITY ISSUE of MimeBleed:
Attachment content is fail-closed on every storage path. Thanks to avrlab233 and xet7.
Slash-separated tags with unquoted event handlers could bypass the markup
sniff, filesystem-destination uploads skipped the validation applied during
storage migration, and Meteor-Files could serve executable stored metadata
inline from its original route. Upload validation now recognizes those handler
and JavaScript-URI forms for every destination. Filesystem, GridFS and cloud
downloads share one response policy that forces HTML, SVG, XML and JavaScript
types or filenames to an opaque attachment with nosniff, frame denial and a
sandboxed CSP. Rejected uploads remain visible as MimeBleed events in Admin
Panel → Problems; ordinary file views are transformed safely rather than logged
because the response path cannot distinguish an attack from a legitimate view.
Mocha covers the reported payload and negative samples, Node coverage pins all
storage shapes, and Chromium, Firefox and WebKit exercise the full download
route.
and fixes the following bugs:
All Boards - sorting uses one reactive choice from the popup through the rendered board grid.
The chosen board order takes effect immediately and remains selected. Thanks to jullbo and xet7.
The profile was updated on the server, but the popup, pagination and board grid continued reading a current-user document that was not guaranteed to be republished after the click. The chosen mode now has an immediate reactive client value, is shared by every sorting consumer, and rolls back if persistence fails. Browser coverage verifies both visible A→Z ordering and the stored profile choice, including the selected state when the popup is reopened.
FerretDB - sorted queries allocate memory for real results instead of a wire-protocol sentinel limit.
Effectively unlimited sorted queries no longer reserve gigabytes up front. Thanks to jeremy-arsia, Heart1010 and xet7.
A client’s ordinary sorted find can express no practical limit as
2147483647. FerretDB used that number as a Go slice’s initial capacity and
could immediately request about 16 GiB, causing high CPU, out-of-memory crashes,
connection resets and temporarily missing boards while the database restarted.
The bounded top-k heap now starts small and grows only for documents that exist.
A maximum-limit regression test verifies correct ordering without the eager
allocation, while the finite-limit test keeps the bounded behavior covered.
and improves developer tooling:
Simultaneous browser users keep independent sessions. Thanks to xet7.
The multi-user stability test opened both users in one browser context, where Meteor’s origin-scoped resume token necessarily made the second login replace the first. It now uses a separate context per user, matching real independent sessions and removing the false timeout while still verifying both board views.
Thanks to above GitHub users for their contributions and translators for their translations.