/Vulnerability Library

Kan <= 0.5.4 - Server-Side Request Forgery

CVE-2026-32255
Verified

Description

Kan, an open-source project management tool (Trello alternative), versions 0.5.4 and below are vulnerable to an unauthenticated Server-Side Request Forgery in the /api/download/attatchment endpoint. The endpoint passes the attacker-controlled `url` query parameter straight to a server-side fetch() without validating the destination host, allowing an unauthenticated attacker to make the server issue arbitrary outbound HTTP requests and read back the full response body.

Severity

High

CVSS Score

8.6

Exploit Probability

2%

Affected Product

kan

Published Date

August 3, 2026

Template Author

prithvee07

CVE-2026-32255.yaml
8.6Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVE ID:
cve-2026-32255
CWE ID:
cwe-918

References

https://github.com/kanbn/kan/security/advisories/GHSA-qrx8-9hc6-jvqghttps://github.com/kanbn/kan/commit/53397d8e81dc1494d94132848c1f0416f1152bd7https://github.com/kanbn/kan/releases/tag/v0.5.5https://github.com/kOaDT/poc-cve-2026-32255https://nvd.nist.gov/vuln/detail/CVE-2026-32255

Remediation Steps

Upgrade Kan to version 0.5.5 or later, which validates the requested host against the configured S3_ENDPOINT before making the upstream request.