GHSA-vcgv-7rvm-m3vpMedium· 4.3▾ SunlitDuplicate Advisory: Vikunja: Link-share token can enumerate users through the v2 API
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-vfxw-3x8p-2vjr. This link is maintained to preserve external references.
Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames exist via the global search endpoint.
code.vikunja.io/api <= 2.5.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-37rx-7pj5-p885High· 7.5Duplicate Advisory: Vikunja: Read-only project members can obtain any link share's access hash via the single-share read endpoint (v1 and v2) and escalate to the share's permission level
GHSA-2922-qgfj-pr7vMedium· 4.3Duplicate Advisory: Vikunja: Any user can enumerate every team and its members by attaching arbitrary teams to a throwaway project
GHSA-8wvg-r2j4-3737MediumVikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint
GHSA-3hc7-r24j-rpwcMediumVikunja: Cross-project task disclosure through subtask expansion
GHSA-9jrx-vmh8-c6xwHigh· 8.1Duplicate Advisory: Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
CVE-2026-57458High· 8.1Vikunja: Scoped API token can mint unrestricted OAuth session credentials