GHSA-ccgq-fx7h-2v4cMedium· 4.3▾ SunlitDuplicate Advisory: Vikunja: Cross-tenant task-position rows can be injected into arbitrary project views via the unvalidated project_view_id in the task position endpoint (v1 and v2)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-w39f-h553-h2mx. This link is maintained to preserve external references.
Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST or PUT task-position endpoints.
code.vikunja.io/api <= 2.5.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-p4r4-8cxw-pjx7Critical· 6.5Duplicate Advisory: Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA)
GHSA-9xwc-vwww-qqmwHigh· 7.5Duplicate Advisory: Vikunja: Link-share principal-type confusion enables cross-account team removal, bot takeover, and roster disclosure
CVE-2026-76216High· 7.5Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards
CVE-2026-55065High· 8.1Vikunja is an open-source self-hosted task management platform
CVE-2026-55066High· 7.1Vikunja is an open-source self-hosted task management platform
CVE-2026-55067Medium· 5.0Vikunja is an open-source self-hosted task management platform