CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-3HC7-R24J-RPWC

GHSA-3hc7-r24j-rpwc: Cross-Project Task Disclosure via Subtask Expansion in Vikunja

Alon Barad
Alon Barad
Software Engineer

Oct 10, 2026·5 min read·4 visits

Executive Summary (TL;DR)

Vikunja API endpoints prior to version 2.6.0 fail to apply project-level authorization filters when recursively expanding subtasks, exposing private task metadata across unauthorized project boundaries.

A cross-project information disclosure vulnerability in Vikunja allows authenticated users with read access to one project to view private task details from unauthorized projects via subtask expansion parameters.

Vulnerability Overview

Vikunja is an open-source task management platform written in Go (code.vikunja.io/api). The application provides REST API endpoints for managing tasks, projects, views, and attachments. Within Vikunja, users can create subtask relationships where a parent task in one project references a child task residing in another project.

A cross-project information disclosure vulnerability exists in all Vikunja versions prior to 2.6.0. When querying tasks using project view endpoints or account-wide task listings, the API accepts the expansion query parameter ?expand[]=subtasks to dynamically populate nested subtasks.

While primary task queries enforce strict access control checks based on the requesting user's project permissions, the subtask expansion routine recursively fetches child tasks without validating project permissions. Consequently, an authenticated attacker with access to a single project can read full details of linked subtasks belonging to private projects where they have no authorization.

> [!WARNING] > This vulnerability exposes complete task structures, including task titles, full descriptions, start and due dates, assigned users, labels, and attachment metadata across unauthorized project boundaries.

Root Cause Analysis

The fundamental flaw stems from missing authorization checks during relational expansion in the HTTP handling and service layer. Vikunja allows tasks in Project P to link to subtasks in Project Q. Creating this link originally requires appropriate permissions in both projects. However, permission rights can change, or tasks can remain linked after user access to Project Q is revoked.

When a client issues an HTTP request with ?expand[]=subtasks, the API router parses the expansion list and invokes relational expansion helpers. The query execution pipeline proceeds in two distinct steps:

First, the primary task database query executes and applies access control filters. For instance, querying /api/v1/projects/1/views/1/tasks ensures that only tasks assigned to Project 1 (and accessible by the requesting user) are returned.

Second, the expansion engine detects the subtasks parameter and walks the relational hierarchy to fetch associated child task records by ID. During this recursive walk, the expansion logic omitted project authorization validation. It retrieved and serialized the full subtask entity directly from the database based solely on foreign key relationships, skipping any checks against the requesting user's permissions for the subtask's host project.

Code Analysis & Authorization Flow

In affected versions of Vikunja, the subtask resolution mechanism operated without contextual permission filtering. The subtask fetching logic queried the database for child tasks matching parent identifiers without wrapping the result set in project boundary checks.

The logic flow can be illustrated as follows:

The patch in pull request #3688 modifies the resource expansion pipeline. Before attaching child subtask entities to the JSON response payload, the handler evaluates the parent project ID of each subtask against the permissions matrix of the requesting context. If the user lacks read permission for the subtask's project, the subtask object is omitted from the expansion array.

Exploitation Mechanics

Exploitation requires valid user credentials and read-level authorization on at least one project containing a parent task linked to a subtask in a restricted project.

An attacker can trigger unauthorized data disclosure by sending an HTTP GET request to either the project view endpoint or the global tasks endpoint while setting the expansion parameter:

GET /api/v1/projects/101/views/1/tasks?expand%5B%5D=subtasks HTTP/1.1
Host: vikunja.example.com
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...

Alternatively, an attacker can query the account-wide task endpoint:

GET /api/v1/tasks?expand%5B%5D=subtasks HTTP/1.1
Host: vikunja.example.com
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...

If a task in Project 101 links to a subtask in restricted Project 202, the JSON response structure exposes the full subtask entity:

{
  "id": 501,
  "title": "Public Parent Task in Project 101",
  "project_id": 101,
  "subtasks": [
    {
      "id": 902,
      "title": "Confidential Internal Subtask in Project 202",
      "description": "Restricted architectural notes and API keys",
      "project_id": 202,
      "assignees": [{"id": 12, "username": "admin"}]
    }
  ]
}

Because the expansion logic functions recursively, nested subtasks beneath subtask ID 902 in Project 202 are also fully populated and leaked.

Impact Assessment

The security impact of GHSA-3hc7-r24j-rpwc is rated with a CVSS v4 score of 6.8 (Medium/High depending on deployment context). The vulnerability affects the confidentiality impact metric (VC:H), as unauthorized authenticated users gain access to sensitive organization data.

leaked information includes complete task content such as titles, technical specifications, internal discussions in task descriptions, user assignment mappings, project timelines, label categorizations, and metadata for attached files.

This flaw is particularly relevant in multi-tenant or enterprise environments where project-level isolation is enforced to segregate departments, teams, or client accounts. Former members whose project access was partially revoked can still leverage remaining access in shared or public projects to extract updates from restricted projects.

Remediation & Mitigation Guidance

The primary remediation for this vulnerability is upgrading the Vikunja backend API instance to version 2.6.0 or later.

To update a standalone or containerized Vikunja instance, apply the patched binary or update the container image tag:

docker pull vikunja/api:v2.6.0
docker-compose up -d

If immediate upgrading is not feasible, administrators can apply network-level or Web Application Firewall (WAF) mitigations by filtering requests containing subtask expansion parameters:

> [!NOTE] > Inspect incoming GET requests to /api/v1/projects/*/views/*/tasks and /api/v1/tasks. Block or strip query strings containing expand[]=subtasks or expand%5B%5D=subtasks.

Official Patches

VikunjaPull Request #3688: fix(security): harden authorization and resource limits
VikunjaVikunja Release v2.6.0

Fix Analysis (1)

Technical Appendix

CVSS Score
6.8/ 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Systems

Vikunja API prior to version 2.6.0 (code.vikunja.io/api)

Affected Versions Detail

Product
Affected Versions
Fixed Version
Vikunja API
Vikunja
< 2.6.02.6.0
AttributeDetail
CWE IDCWE-200 / CWE-285 / CWE-862
Attack VectorNetwork (Remote REST API)
CVSS v4 Score6.8 (Medium)
Privileges RequiredLow (Authenticated user with access to at least one project)
User InteractionNone
Exploit StatusProof of Concept Available
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor

The software exposes sensitive information to an actor that is not authorized to have access to that information.

Known Exploits & Detection

Vendor Advisory (GHSA-3hc7-r24j-rpwc)Proof of concept HTTP requests demonstrating parameter expansion exploitation.

Vulnerability Timeline

Vulnerability identified and disclosure process initiated
2026-08-30
GitHub Security Advisory GHSA-3hc7-r24j-rpwc published
2026-10-09
Vikunja version 2.6.0 released with patch
2026-10-09

References & Sources

  • [1]GitHub Security Advisory GHSA-3hc7-r24j-rpwc
  • [2]Vikunja Pull Request #3688
  • [3]Vikunja Fix Commit 077dc4de79ce6f1ab59215a2c7bf9b30423685f2
  • [4]Vikunja v2.6.0 Release Tag
  • [5]Vikunja Code Repository

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•15 minutes ago•GHSA-G38J-7V97-X298
6.5

GHSA-G38J-7V97-X298: Missing Authorization Check in Vikunja CalDAV Task Relation Creation

In Vikunja prior to version 2.6.0, relation creation via the CalDAV endpoint fails to invoke the TaskRelation.CanCreate authorization check. This missing access control allows an authenticated user to establish unauthorized relationships and perform write operations against any task, provided its unique identifier (UID) is known.

Alon Barad
Alon Barad
1 views•5 min read
•about 2 hours ago•GHSA-8WVG-R2J4-3737
4.3

GHSA-8wvg-r2j4-3737: Email Address Exposure in Vikunja Task Assignees API

An information disclosure vulnerability in Vikunja allows authenticated users with read access to a task to expose private email addresses of assigned users through the API task assignees endpoint due to an unmasked database query.

Amit Schendel
Amit Schendel
4 views•5 min read
•about 3 hours ago•GHSA-W2CH-4XGR-22WW
5.3

GHSA-W2CH-4XGR-22WW: Missing Authorization in Vikunja Task Relation Deletion

An authorization bypass vulnerability in Vikunja versions prior to v2.6.0 permits authenticated users to delete relationships between tasks across project boundaries without requiring read or write authorization for the target related task.

Alon Barad
Alon Barad
5 views•5 min read
•about 4 hours ago•CVE-2026-108258
6.9

CVE-2026-108258: Path Traversal in Shiny for Python Bookmark Restoration

A path traversal vulnerability in Shiny for Python (posit-dev/py-shiny) versions 1.4.0 through 1.6.3 allows unauthenticated remote attackers to read arbitrary files and traverse directories via crafted _state_id_ query parameters.

Alon Barad
Alon Barad
3 views•4 min read
•about 5 hours ago•CVE-2026-108260
7.6

CVE-2026-108260: Stored Cross-Site Scripting (XSS) in @tinacms/web-components

A Stored Cross-Site Scripting vulnerability in @tinacms/web-components prior to version 0.2.1 allows low-privileged content authors to execute arbitrary JavaScript code in the context of website visitors via unsanitized URL attributes in custom Markdown rendering components.

Alon Barad
Alon Barad
4 views•5 min read
•about 6 hours ago•CVE-2026-108261
9.3

CVE-2026-108261: Admin Preview Cross-Origin Bypass and GraphQL Hijacking in TinaCMS

A critical origin validation flaw in TinaCMS admin preview allows unauthenticated attackers to bypass cross-origin postMessage checks and execute unauthorized GraphQL queries and mutations under an authenticated editor's context.

Alon Barad
Alon Barad
7 views•5 min read