Security: go-vikunja/vikunja
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA)GHSA-rj9j-8772-4h6c published
Jul 19, 2026 by kolaenteHigh -
OIDC email-fallback account linking ignores email_verified, enabling local-account takeoverGHSA-xv7q-fvmc-jx96 published
Jul 19, 2026 by kolaenteHigh -
Plaintext storage of password-reset/email-confirm tokens in database enables account takeover on DB read accessGHSA-r6w9-259g-gwrv published
Jul 19, 2026 by kolaenteHigh -
Project duplication bypasses write-permission check on the target parent projectGHSA-f27p-pw2p-9pr4 published
Jul 19, 2026 by kolaenteModerate -
Authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignmentGHSA-569v-q83c-3j3g published
Jul 19, 2026 by kolaenteModerate -
Scoped API token can mint unrestricted OAuth session credentialsGHSA-v3p6-34mc-hj7v published
Jul 19, 2026 by kolaenteHigh -
Cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_idGHSA-5pg6-m483-7vrg published
Jul 19, 2026 by kolaenteHigh -
Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/apiGHSA-gg93-x632-9ccv published
Jul 19, 2026 by kolaenteHigh -
Incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0GHSA-44v6-7fxq-vgf4 published
Jul 19, 2026 by kolaenteModerate -
Scoped API tokens with projects.background permission can delete project backgroundsGHSA-v479-vf79-mg83 published
Apr 9, 2026 by kolaenteModerate