VYPR

Kan

by Kanbn

Source repositories

CVEs (2)

  • CVE-2026-32255HigMar 19, 2026
    risk 0.50cvss 8.6epss 0.02

    Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts a user-supplied URL query parameter and passes it directly to fetch()…

  • CVE-2026-92802MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create…