A critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-32255, in the open-source project management tool Kan, has been confirmed as exploited in the wild. The flaw, which affects versions 0.5.4 and earlier, allows an unauthenticated attacker to make arbitrary HTTP requests from the server, potentially accessing internal services, cloud metadata endpoints, or private network resources.
The vulnerability resides in the `/api/download/attatchment` endpoint, which lacks both authentication and URL validation. This endpoint directly passes a user-supplied URL query parameter to a server-side `fetch()` function, subsequently returning the full response body to the attacker.
The existence of the vulnerability was publicly disclosed on March 19, 2026, and it was added to the VulnCheck Known Exploited Vulnerabilities (KEV) catalog on September 17, 2026, approximately 182 days after its initial disclosure. The Computer Emergency Response Center Luxembourg (CIRCL) aggregator also listed the vulnerability as exploited on the same date. However, it has not yet been included in the CISA KEV or the ENISA (European Union Agency for Cybersecurity) KEV.
The Kan project has addressed this issue in version 0.5.5. For users unable to upgrade immediately, a recommended workaround involves blocking or restricting access to the `/api/download/attatchment` endpoint at the reverse proxy level, using tools like Nginx or Cloudflare.
The vulnerability carries a CVSS score of 8.6, indicating high severity, and is categorized under CWE-918, which refers to Server-Side Request Forgery. Its EPSS (Exploit Prediction Scoring System) percentile is 77.0%, suggesting a moderate likelihood of exploitation. Public reports related to the vulnerability and its exploitation began appearing on March 19, 2026, coinciding with the disclosure date.






