GHSA-9jrx-vmh8-c6xwHigh· 8.1▾ TwilightDuplicate Advisory: Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-vvcv-vpph-h844. This link is maintained to preserve external references.
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tokens endpoints. An authenticated attacker can obtain a target's numeric user ID via authenticated user search, then create link shares on an attacker-writable project until the link-share sequence reaches that value, and use the resulting link-share JWT to list, create, and delete the target user's API tokens (including issuing a new token with attacker-chosen scopes under the target's permissions). Fixed in version 2.4.0.
code.vikunja.io/api >= 0.22.0, <= 2.3.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68581High· 8.1Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management
GHSA-phph-c358-5mwmMedium· 4.3Duplicate Advisory: Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts)
GHSA-fprf-r6rv-xg99Medium· 5.4Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants
GHSA-fmmf-xq98-g327MediumVikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check
GHSA-hjx8-qv73-f7cmMedium· 6.5Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed
CVE-2026-76216High· 7.5Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards