---
id: GHSA-8wvg-r2j4-3737
title: >-
  Vikunja: Assignee email addresses disclosed to read-only project members via
  the task assignees endpoint
summary: >-
  Vikunja: Assignee email addresses disclosed to read-only project members via
  the task assignees endpoint
severity: medium
cwe:
  - CWE-200
vendor: api
product: code.vikunja.io/api
ecosystem: go
affected:
  - code.vikunja.io/api <= 2.5.0
patched:
  - code.vikunja.io/api 2.6.0
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:54:51Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-8wvg-r2j4-3737'
references:
  - url: >-
      https://github.com/go-vikunja/vikunja/security/advisories/GHSA-8wvg-r2j4-3737
  - url: 'https://github.com/go-vikunja/vikunja/pull/3688'
  - url: 'https://github.com/go-vikunja/vikunja/releases/tag/v2.6.0'
  - url: 'https://github.com/advisories/GHSA-8wvg-r2j4-3737'
tags:
  - ghsa
  - go
ingestedAt: '2026-10-09T21:12:42.324Z'
---

## Overview

### Summary
`TaskAssginee.ReadAll` returns assignee user objects without blanking the `Email` field, disclosing assignee email addresses to any read-only project member. Every sibling path that returns user objects obfuscates the email; this one does not.

### Details
`pkg/models/task_assignees.go` (~lines 306-344) does `Select("users.*")` and returns the result directly. `User.Email` is `json:"email,omitempty"`, so a non-empty value always serializes. The endpoint gates on `task.CanRead`, so a read-only member passes. Sibling paths blank the field: `pkg/models/tasks.go:530`, `pkg/models/project_users.go:216`, `pkg/models/teams.go:177`, `pkg/models/label_task.go:312`, `pkg/models/task_attachment.go:511`. The omission here reads as an oversight, not a decision.

The same file's `getRawTaskAssigneesForTasks` (~line 56) also selects `users.*` but is safe because its only caller (`addAssigneesToTasks`) blanks the email afterwards.

### PoC (verified at runtime against v2.5.0, v1 and v2)
```
GET /api/v1/tasks/{id}/assignees   (reader with permission:0)
-> [{"id":37,"username":"...","email":"assignee+SECRET@example.test", ...}]
```
Same leak on `GET /api/v2/tasks/{id}/assignees` (routes through the identical model method). Contrast: `GET /api/v1/projects/{id}/projectusers` and the project task-embed both return the same users with no email.

### Impact
Disclosure of assignees' email addresses to users who should only see usernames. Read-only.

### Fix
Blank `Email` on each returned user in `TaskAssginee.ReadAll` before returning, matching the sibling paths. Covers v1 and v2 at once.

## Affected packages

- `code.vikunja.io/api <= 2.5.0`

## Remediation

Upgrade to a patched release:

- `code.vikunja.io/api 2.6.0`
