GHSA-37rx-7pj5-p885High· 7.5▾ TwilightDuplicate Advisory: Vikunja: Read-only project members can obtain any link share's access hash via the single-share read endpoint (v1 and v2) and escalate to the share's permission level
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-qfwc-vx6f-3g6g. This link is maintained to preserve external references.
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.
code.vikunja.io/api <= 2.5.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-2922-qgfj-pr7vMedium· 4.3Duplicate Advisory: Vikunja: Any user can enumerate every team and its members by attaching arbitrary teams to a throwaway project
GHSA-vcgv-7rvm-m3vpMedium· 4.3Duplicate Advisory: Vikunja: Link-share token can enumerate users through the v2 API
GHSA-8wvg-r2j4-3737MediumVikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint
GHSA-3hc7-r24j-rpwcMediumVikunja: Cross-project task disclosure through subtask expansion
GHSA-9jrx-vmh8-c6xwHigh· 8.1Duplicate Advisory: Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
CVE-2026-57458High· 8.1Vikunja: Scoped API token can mint unrestricted OAuth session credentials