GHSA-2922-qgfj-pr7vMedium· 4.3▾ SunlitDuplicate Advisory: Vikunja: Any user can enumerate every team and its members by attaching arbitrary teams to a throwaway project
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-39p5-2wrr-xh29. This link is maintained to preserve external references.
vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve complete team rosters including member names and admin flags for unauthorized teams.
code.vikunja.io/api <= 2.5.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-37rx-7pj5-p885High· 7.5Duplicate Advisory: Vikunja: Read-only project members can obtain any link share's access hash via the single-share read endpoint (v1 and v2) and escalate to the share's permission level
GHSA-vcgv-7rvm-m3vpMedium· 4.3Duplicate Advisory: Vikunja: Link-share token can enumerate users through the v2 API
GHSA-8wvg-r2j4-3737MediumVikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint
GHSA-3hc7-r24j-rpwcMediumVikunja: Cross-project task disclosure through subtask expansion
GHSA-9jrx-vmh8-c6xwHigh· 8.1Duplicate Advisory: Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
CVE-2026-57458High· 8.1Vikunja: Scoped API token can mint unrestricted OAuth session credentials