GHSA-phph-c358-5mwmMedium· 4.3▾ SunlitDuplicate Advisory: Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-9rg3-v78m-26q8. This link is maintained to preserve external references.
Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without proper permission verification.
code.vikunja.io/api >= 1.0.0, <= 2.5.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-9jrx-vmh8-c6xwHigh· 8.1Duplicate Advisory: Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
GHSA-fprf-r6rv-xg99Medium· 5.4Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants
GHSA-fmmf-xq98-g327MediumVikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check
GHSA-hjx8-qv73-f7cmMedium· 6.5Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed
CVE-2026-76216High· 7.5Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards
CVE-2026-54766MediumVikunja is an open-source self-hosted task management platform