VYPR
Vendor

Kanbn

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2026-32255HigMar 19, 2026
    risk 0.50cvss 8.6epss 0.02

    Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts a user-supplied URL query parameter and passes it directly to fetch()…

  • CVE-2026-92802MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create…