Impact
The vulnerability exists because kan up to version 0.6.0 does not properly verify that a user has board‑creation rights when the GitHub project import endpoint is used. Based on the description, it is inferred that guests who normally lack the required board:create permission can exploit the importProjects mutation to create new boards, thereby bypassing existing permission checks.
Affected Systems
The affected product is kan developed by kanbn. Versions up to and including 0.6.0 are impacted. The issue is triggered via the import endpoint found in the kan API, specifically the routes that handle GitHub project imports.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity. The EPSS score is less than 1 %, showing a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the importProjects mutation over the network, which can be invoked by an authenticated guest user. Once exploited, an attacker can create arbitrary boards and potentially use them to store or manipulate data.
OpenCVE Enrichment