NIXPKGS-2026-0223
GitHub issue
published on 11 Feb 2026
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
Kanboard is missing authorization check in getSwimlane API allows cross-project data access
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane data from projects they cannot access. This vulnerability is fixed in 1.2.50.
Affected products
kanboard
- ==< 1.2.50
Package maintainers
-
@yzx9 Zexin Yuan <yuan.zx@outlook.com>