Wekan logo

Wekan

Open source kanban board application built with Meteor

Alternative to: trello


About Versions (307)

v11.77

2026-09-14

v11.77 2026-09-14 WeKan ® release

In short: Tamazight rules, search, email, attachments and maintenance labels replace French and inconsistent terminology. Bambara and Fulah calendar labels also receive repairs. Actions, qualifiers and placeholders are preserved; provisional calendar and complete software wording still need language review.

This release includes the following translation repairs and build verification:

This release fixes the following CRITICAL SECURITY ISSUES:

Security - Board policies, role capabilities and object boundaries.

Enforce private-only policy for trusted board insertions

Copies, imports and helper-created boards now obey the instance private-only policy at the shared insertion hook. A public insertion becomes private; logging failure cannot bypass enforcement. Targeted policy and visibility settings tests pass. Live browser/server verification remains pending.

Enforce private-only board visibility in server methods

VisibilityBleed: direct board creation and card-to-board conversion could create public boards despite the instance private-only policy (CWE-863). Both paths now force private visibility before insertion. Blocked overrides appear as bounded Admin Panel Problems summaries; logging failures cannot break the policy. Reporter: Wenhao Wu, Southeast University. Positive policy, negative board-insert inventory and Hall of Fame catalog coverage pass. Browser regression is added and syntax-checked; live execution remains pending. The remaining wekansec21 review is tracked in the security remediation report.

Thanks to Wenhao Wu, Southeast University and xet7 !

Require write capability for board mutations

MutationBleed: membership-only method checks allowed comment-only and other non-writing roles to mutate data (CWE-863). List and swimlane moves now require write access on both boards; checklist moves check both card boards. Scoped imports, attachment renames and history writes use the same canonical role policy. The No comments role retains its intended write access. Denied writes produce bounded Problems summaries; logger failures cannot bypass the guard. Role-matrix, method-attack and sibling inventory tests pass. Browser regression is added and syntax-checked; live execution remains pending. The remaining wekansec21 review is tracked in the remediation report.

Thanks to Wenhao Wu, Southeast University and xet7 !

Bind comments to the authorized card board

CommentBoundaryBleed: REST and DDP inserts accepted a foreign card ID on an authorized board, injecting comments onto private cards (CWE-639). Both now require the card to belong to the requested board. DDP cannot rebind existing comment identities to bypass insertion checks. Legacy comment listing remains card-authoritative after board validation. Denied attempts appear in bounded Problems summaries. Attack decisions, negative server insert inventory and existing REST ACL suites pass. Browser regression is syntax-checked; live execution remains pending. Remaining reports are tracked in the security remediation report.

Thanks to Wenhao Wu, Southeast University and xet7 !

Require administrators for REST board management

ManageBoardBleed: normal members could rename boards, change card settings and configure trusted automation over REST (CWE-863). These management endpoints now use the existing board-administrator guard, including site-admin access. Denials produce bounded Problems summaries. Actual guard decisions, endpoint inventory, card-settings and rule suites pass. Browser regression is syntax-checked; live execution remains pending.

Thanks to Wenhao Wu, Southeast University and xet7 !

Bind button rules to a writable board and its card

RuleButtonBleed: a board member could run a button rule against a foreign private card, bypassing collection authorization (CWE-639). Manual rules now require write capability and a card belonging to the rule board, both before dispatch and in the shared action dispatcher. Cardless board buttons remain supported. Denials appear in bounded Problems summaries. Role and boundary decisions, dispatcher inventory and existing rule suites pass. Browser regression is syntax-checked; live execution remains pending.

Thanks to Wenhao Wu, Southeast University and xet7 !

Protect server-issued board invitation fields

InviteProfileBleed: removed members could forge client-writable invitation fields and reactivate membership (CWE-863). Profile invitation capabilities are now server-controlled, including array and rename operations and parent replacement. Modifier-path checks preserve ordinary preference updates. Blocked invitation changes appear in bounded Problems summaries. Guard and existing invitation suites pass; browser regression is syntax-checked with live execution pending.

Thanks to Wenhao Wu, Southeast University and xet7 !

Replace the activity test sanitizer stub with the real parser

Code scanning alert 540 points to a regex substitute in a test, rather than an application sanitizer. The test now uses the existing sanitize-html parser and covers malformed script closing tags. Positive and negative checks pass. This test-only change has no runtime attack event to log and no new application vulnerability is claimed.

Thanks to GitHub CodeQL and xet7 !

Authorize each board in registration invitations

InvitationBoardBleed: domain-approved registration inviters could include arbitrary private boards in invitation grants (CWE-639). Every board now requires the configured inviter role or site-admin access, and must exist. The complete grant is checked before code mutations or outgoing mail. Blocked grants appear in bounded Problems summaries. Role/grant inventory and email suites pass; browser regression is syntax-checked. Live mail and redemption were not executed.

Thanks to Wenhao Wu, Southeast University and xet7 !

Prevent linked cards from promoting source read roles

LinkedWriteBleed: a comment-only source member could mint a link on a self-owned board and gain source writes (CWE-863). Link creation and DDP pointer changes now require source write access. Explicit non-writing source roles also block delegation through existing links. UI permissions follow that ceiling; non-writers no longer receive the link action. Denied writes appear in bounded Problems summaries. Actual role/permission and link inventory tests pass; browser regression is syntax-checked, with live execution pending.

Thanks to Wenhao Wu, Southeast University and xet7 !

Authorize subtask deposit content and destination writes

SubtaskDepositBleed: an arbitrary deposit pointer disclosed private board content and allowed unauthorized subtask inserts (CWE-639). Source scopes exclude foreign pointers and null IDs. Deposit content now follows its own reactive board visibility check and destination assignment restrictions. Assigned-card children follow reactive card cursors; status counts use visible assigned scopes. Destination write checks precede landing structures and pointer changes, including a client rename bypass. Denied writes appear in bounded Problems summaries. Normal filtered reads are not attack events. Decision/scope and existing subtask/status tests pass. Browser regression is syntax-checked; live revocation and DDP execution remain pending.

Thanks to Wenhao Wu, Southeast University and xet7 !

Translations - Tamazight interface and maintenance labels; Bambara, Fulah, Dzongkha and Ewe calendars.

Thanks to above GitHub users for their contributions and translators for their translations.

More details at ChangeLog