CVE-2025-55011

NameCVE-2025-55011
DescriptionKanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does not validate whether the task_id parameter is a valid task id, nor does it check for path traversal. As a result, a malicious actor could write a file anywhere on the system the app user controls. The impact is limited due to the filename being hashed and having no extension. This issue has been patched in version 1.2.47.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1112364

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kanboard (PTS)sid1.2.47+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kanboardsource(unstable)1.2.47+ds-11112364

Notes

https://github.com/kanboard/kanboard/security/advisories/GHSA-26f4-rx96-xc55
https://github.com/kanboard/kanboard/commit/523a6135e944b6884c091a3fd7605af8ef13368 (v1.2.47)

Search for package or bug name: Reporting problems