---
id: CVE-2026-57458
title: Vikunja is an open-source self-hosted task management platform
summary: >-
  Vikunja is an open-source self-hosted task management platform. In version
  2.3.0, a scoped API token limited to the `oauth.authorize` permission can call
  `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and
  exchange th…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-269
vendor: api
product: code.vikunja.io/api
affected:
  - code.vikunja.io/api = 2.3.0
patched:
  - code.vikunja.io/api 2.4.0
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T21:17:05.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57458'
references:
  - url: >-
      https://github.com/go-vikunja/vikunja/commit/4ae2e093014881052ed8f8ecd8bcb9adf83dd276
    label: security-advisories@github.com
  - url: 'https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/go-vikunja/vikunja/security/advisories/GHSA-v3p6-34mc-hj7v
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-v3p6-34mc-hj7v'
tags:
  - nvd
  - ghsa
  - go
aliases:
  - GHSA-v3p6-34mc-hj7v
ecosystem: go
ingestedAt: '2026-10-09T21:12:42.335Z'
---

## Overview

Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at `POST /api/v1/oauth/token` for a normal bearer JSON Web Token (JWT) and refresh token. The resulting credentials are not restricted by the original API token's permissions, allowing access to routes outside its declared scope for the same user. Version 2.4.0 fixes the vulnerability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-57458)

Affected packages:

- `code.vikunja.io/api = 2.3.0`

Patched in:

- `code.vikunja.io/api 2.4.0`

Source: https://github.com/advisories/GHSA-v3p6-34mc-hj7v
