{"id":"GHSA-vcgv-7rvm-m3vp","title":"Duplicate Advisory: Vikunja: Link-share token can enumerate users through the v2 API","summary":"Duplicate Advisory: Vikunja: Link-share token can enumerate users through the v2 API","severity":"medium","cvss":4.3,"cwe":["CWE-200"],"vendor":"api","product":"code.vikunja.io/api","ecosystem":"go","affected":["code.vikunja.io/api <= 2.5.0"],"published":"2026-09-15","updated":"2026-10-09","sourceUpdated":"2026-10-09T20:52:34Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-vcgv-7rvm-m3vp","references":[{"url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-vfxw-3x8p-2vjr"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91981"},{"url":"https://www.vulncheck.com/advisories/vikunja-before-2.6.0-user-enumeration-via-v2-api"},{"url":"https://github.com/advisories/GHSA-vcgv-7rvm-m3vp"}],"tags":["ghsa","go"],"ingestedAt":"2026-10-09T21:12:42.328Z","slug":"GHSA-vcgv-7rvm-m3vp","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-vfxw-3x8p-2vjr. This link is maintained to preserve external references.\n\n### Original Description\nVikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames exist via the global search endpoint.\n\n## Affected packages\n\n- `code.vikunja.io/api <= 2.5.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}