kan through 0.6.0 Authorization Bypass via GitHub Project Import
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
kanbn · kanReferences
https://github.com/kanbn/kanhttps://github.com/kanbn/kan/blob/f08920d/packages/api/src/routers/import.ts#L259https://github.com/kanbn/kan/blob/v0.6.0/packages/api/src/routers/import.ts#L622-L670https://github.com/kanbn/kan/issues/628https://www.vulncheck.com/advisories/kan-through-0.6.0-authorization-bypass-via-github-project-import