PT-2026-94076 · Git+1 · Kan
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
kan versions prior to 0.6.1
Description
Insufficient validation of board creation permissions occurs in the GitHub project import endpoint. This allows guests to create boards even if they lack the
board:create permission. An attacker can bypass authorization checks by utilizing the importProjects mutation to create boards, bypassing the restrictions placed on direct creation paths.Recommendations
Update kan to version 0.6.1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kan