{"id":"GHSA-jmr8-r558-3jhx","title":"Duplicate Advisory: Vikunja: TOTP secret is readable after enrollment, no step-up auth","summary":"Duplicate Advisory: Vikunja: TOTP secret is readable after enrollment, no step-up auth","severity":"medium","cvss":4.3,"cwe":["CWE-522"],"vendor":"api","product":"code.vikunja.io/api","ecosystem":"go","affected":["code.vikunja.io/api <= 2.5.0"],"published":"2026-09-15","updated":"2026-10-09","sourceUpdated":"2026-10-09T20:51:11Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-jmr8-r558-3jhx","references":[{"url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-88f6-4rjv-x774"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91982"},{"url":"https://www.vulncheck.com/advisories/vikunja-before-2.6.0-totp-secret-disclosure-via-api"},{"url":"https://github.com/advisories/GHSA-jmr8-r558-3jhx"}],"tags":["ghsa","go"],"ingestedAt":"2026-10-09T21:12:42.331Z","slug":"GHSA-jmr8-r558-3jhx","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-88f6-4rjv-x774. This link is maintained to preserve external references.\n\n### Original Description\nVikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication. Attackers with a valid access token can read the secret, import it into their own authenticator, and generate valid codes indefinitely to defeat the second factor and enable account takeover.\n\n## Affected packages\n\n- `code.vikunja.io/api <= 2.5.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}