GHSL-2026-036: Potential Sensitive Token Exposure and Unauthorized Access in Wekan - CVE-2026-30845
Published Mar 6, 2026
·Updated
The Wekan project version v8.31.0 is affected by a vulnerability (GHSL-2026-036) involving a webhook token leak through the pubsub mechanism, potentially exposing sensitive tokens and enabling unauthorized access or actions.
Affected Software
1 affected component
Wekan Wekan=8.31.0
Event History
Mar 6, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of GHSL-2026-036?
The severity of GHSL-2026-036 is rated as 60, indicating a moderate risk level.
2
How do I fix GHSL-2026-036?
To fix GHSL-2026-036, upgrade to Wekan version 8.34 or later to mitigate the token leak.
3
What is the main issue of GHSL-2026-036?
GHSL-2026-036 involves a vulnerability that causes webhook tokens to be exposed through the pubsub mechanism.
4
Who is affected by GHSL-2026-036?
The vulnerability GHSL-2026-036 affects users of Wekan version v8.31.0.
5
What could happen if GHSL-2026-036 is exploited?
Exploitation of GHSL-2026-036 could lead to unauthorized access or actions due to the exposure of sensitive webhook tokens.