Kan <= 0.5.4 - Server-Side Request Forgery
CVE-2026-32255
Verified
Description
Kan, an open-source project management tool (Trello alternative), versions 0.5.4 and below are vulnerable to an unauthenticated Server-Side Request Forgery in the /api/download/attatchment endpoint. The endpoint passes the attacker-controlled `url` query parameter straight to a server-side fetch() without validating the destination host, allowing an unauthenticated attacker to make the server issue arbitrary outbound HTTP requests and read back the full response body.
Severity
High
CVSS Score
8.6
Exploit Probability
2%
Affected Product
kan
Published Date
August 3, 2026
Template Author
prithvee07
CVE-2026-32255.yaml
8.6Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVE ID:
cve-2026-32255
CWE ID:
cwe-918
Remediation Steps
Upgrade Kan to version 0.5.5 or later, which validates the requested host against the configured S3_ENDPOINT before making the upstream request.