Security: go-vikunja/vikunja
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Arbitrary local application invocation via unvalidated shell.openExternal in Vikunja DesktopGHSA-6q44-85gc-cjvf published
Mar 20, 2026 by kolaenteHigh -
Remote Code Execution via same-window navigation in Vikunja DesktopGHSA-83w9-9jf6-88vf published
Mar 20, 2026 by kolaenteCritical -
IDOR in Task Comments Allows Reading Arbitrary CommentsGHSA-mr3j-p26x-72x4 published
Mar 20, 2026 by kolaenteModerate -
Read-only users can delete project background images via broken object-level authorizationGHSA-564f-wx8x-878h published
Mar 20, 2026 by kolaenteModerate -
2FA Bypass via Caldav Basic AuthGHSA-47cr-f226-r4pq published
Mar 20, 2026 by kolaenteModerate -
Improper Access Control Enables Bypass of Administrator-Imposed Account DisablementGHSA-vq4q-79hh-q767 published
Mar 20, 2026 by kolaenteHigh -
TOTP Reuse During Validity WindowGHSA-p747-qc5p-773r published
Mar 20, 2026 by kolaenteModerate -
DoS via Image Preview GenerationGHSA-wc83-79hj-hpmq published
Mar 20, 2026 by kolaenteHigh -
Rate-Limit Bypass for Unauthenticated Users via Spoofed HeadersGHSA-m547-hp4w-j6jx published
Mar 20, 2026 by kolaenteModerate -
Account Takeover via Password Reset Token ReuseGHSA-rfjg-6m84-crj2 published
Feb 27, 2026 by kolaenteCritical