CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-FPRF-R6RV-XG99

GHSA-FPRF-R6RV-XG99: Cross-Tenant Task Position Recalculation in Vikunja

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 10, 2026·4 min read·5 visits

Executive Summary (TL;DR)

Creating a saved filter with an empty filter string in Vikunja triggers task position recalculation across all database tenants, resulting in cross-tenant data integrity corruption and potential service degradation.

A cross-tenant boundary breach vulnerability in Vikunja allows an authenticated user to trigger global task position recalculations across all tenant instances by creating a saved filter with an empty filter string payload.

Vulnerability Overview

Vikunja is an open-source task management application designed to support multi-tenant operational environments. Multi-tenancy relies on database boundary isolation to ensure that tasks, user filters, and project configurations created by one tenant remain strictly segregated from all other tenants sharing the application infrastructure.

The vulnerability designated as GHSA-FPRF-R6RV-XG99 is a cross-tenant state alteration bug within the saved filter management system. When an authenticated user creates a saved filter containing an empty filter parameter, the application logic fails to restrict the subsequent recalculation of task positions to the user's specific tenant context.

This improper scope restriction permits an unprivileged attacker in one tenant workspace to involuntarily reorder and update task positions across every tenant hosted on the target Vikunja instance, violating multi-tenant isolation guarantees.

Root Cause Analysis

The root cause of GHSA-FPRF-R6RV-XG99 originates from inadequate constraint enforcement during saved filter initialization and background task reordering routines. In Vikunja, saved filters allow users to store criteria queries that organize and display tasks dynamically.

When a filter string is populated with criteria (such as priority level or project tags), the backend constructs a tenant-scoped database query that applies strictly to the current user context. However, when an empty filter string ("") is processed, the criteria evaluation engine defaults to an unconstrained query pattern.

Because the background position recalculation task omits tenant predicate checks (tenant_id = ?) when handling empty filter conditions, the reordering script evaluates every task row present in the central database table. This causes universal task position recalculation across all tenant spaces.

Code & Execution Flow Analysis

The execution path transitions from an incoming user API request to an un-scoped database mutation across tenant boundaries.

When evaluating filter persistence, the application invokes a routine designed to recalculate positional indexes for tasks belonging to the filter. Because the empty string bypasses criteria parsing, the underlying query generator fails to attach tenant context identifiers, resulting in global UPDATE execution.

Exploitation & Threat Vector

Exploitation requires basic authenticated access to any valid account within a multi-tenant Vikunja deployment. Elevated administrative privileges are not required to trigger the issue.

An attacker sends an HTTP POST request to the API endpoint responsible for saved filter creation, supplying an empty string inside the filter parameter payload:

{
  "title": "Malicious Filter",
  "filter": ""
}

Upon parsing this request, the backend immediately executes the global task index recalculation. Task ordering indexes belonging to external organizations and unrelated users are overwritten, disrupting sequence views and custom board arrangements across the entire system.

Impact Assessment

The impact of GHSA-FPRF-R6RV-XG99 affects both data integrity and service availability in multi-tenant deployment scenarios. While direct exfiltration or unauthorized read access to task content does not occur, multi-tenant security guarantees are breached.

Data integrity is compromised as task position values across all tenants are modified without authorization. This disrupts project management workflows, custom task reordering, and Kanban view arrangements for all active users on the server.

From an availability perspective, executing batch updates across all database records in large multi-tenant instances creates severe database CPU usage spikes and table lock contention, leading to response timeouts or denial of service.

Remediation & Patching Guidance

Deployments running Vikunja should update to patched software versions that enforce strict tenant filtering on all filter creation and task position recalculation operations.

Application developers must ensure that all background database routines incorporate mandatory tenant ID scoping predicates, preventing queries from operating outside the requester's context even when parameter evaluation produces empty or default filter trees.

> [!NOTE] > If an immediate patch deployment is not feasible, web application firewalls (WAF) or API gateways can be configured to filter out requests targeting the saved filter creation route containing empty filter field values.

Technical Appendix

CVSS Score
6.5/ 10

Affected Systems

Vikunja multi-tenant deployments
AttributeDetail
Vulnerability IDGHSA-FPRF-R6RV-XG99
CWE IDCWE-284 (Improper Access Control)
Attack VectorNetwork / Remote
Privileges RequiredLow (Authenticated User)
ImpactCross-Tenant State Modification / Integrity Breach
Exploit StatusPoC Method Documented

References & Sources

  • [1]GitHub Security Advisory GHSA-FPRF-R6RV-XG99

More Reports

•34 minutes ago•GHSA-4HV6-XC92-J86G
6.5

GHSA-4HV6-XC92-J86G: Insufficient Session Expiration in Vikunja WebSocket Authentication Pipeline

Vikunja versions 2.3.0 through 2.6.0 contain an insufficient session expiration vulnerability (CWE-613) within the WebSocket authentication handler. Although Vikunja enforces server-side session tracking and revocation for REST API routes, the WebSocket handshake handler validates cryptographic JWT signatures without querying the database session state. Consequently, revoked JWT tokens can establish new real-time WebSocket connections, and existing connections persist after session revocation.

Alon Barad
Alon Barad
1 views•5 min read
•about 3 hours ago•GHSA-HJX8-QV73-F7CM
6.5

GHSA-HJX8-QV73-F7CM: Incomplete Access Revocation Leading to Webhook Data Exfiltration in Vikunja

An access revocation flaw in Vikunja allows removed collaborators to retain outbound webhooks and link shares created prior to revocation, enabling persistent exfiltration of sensitive task data.

Alon Barad
Alon Barad
5 views•5 min read
•about 4 hours ago•GHSA-PJR3-86V4-5P7W
5.4

GHSA-PJR3-86V4-5P7W: Broken Access Control via MAX Aggregation in Vikunja Subtree Permissions

Vikunja v2.6.0 contains a permission inheritance regression in pkg/models/project_access.go where explicit down-restrictions on sub-projects are overridden by higher parent project permissions due to MAX aggregation across project tree nodes.

Alon Barad
Alon Barad
5 views•6 min read
•about 5 hours ago•GHSA-FMMF-XQ98-G327
5.3

GHSA-fmmf-xq98-g327: Write-Level Project Members Can Delete Admin-Tier Link Shares in Vikunja

An authorization bypass vulnerability in Vikunja's link share deletion handlers allows project members with Write privileges to delete Admin-tier link shares. The handler passes an unpopulated struct to the authorization check, causing the permission evaluation to fall back to default Write permissions instead of requiring Admin privileges.

Alon Barad
Alon Barad
8 views•5 min read
•about 6 hours ago•GHSA-M687-P538-R5HP
7.2

GHSA-m687-p538-r5hp: Permissive Localhost CORS Policy Leads to Account Takeover in Vikunja

Vikunja versions 2.2.0 through 2.6.0 contain a Cross-Origin Resource Sharing (CORS) misconfiguration flaw in `code.vikunja.io/api`. Default configurations permit wildcard origins for localhost (`http://127.0.0.1:*` and `http://localhost:*`) with credentialed requests (`Access-Control-Allow-Credentials: true`). Because configuring a public service URL appends to this default list rather than overriding it, production environments inadvertently trust all local origins. A local page or application on a user's machine can execute a credentialed cross-origin request to the token refresh endpoint, extract the returned JWT access token, and achieve complete account takeover.

Alon Barad
Alon Barad
8 views•5 min read
•about 12 hours ago•GHSA-JQ7H-WRVP-3RGX
7.5

GHSA-JQ7H-WRVP-3RGX: Insufficient Session Invalidation in pyLoad Core REST API

An insufficient session invalidation vulnerability exists in pyLoad (pyload-ng) versions 0.5.0b3.dev98 through 0.5.0b3.dev101. When administrative actions like privilege revocation or password changes are executed via the public REST API, active user sessions on disk are not updated or invalidated. Consequently, affected sessions remain fully authenticated with stale permissions for up to 31 days.

Amit Schendel
Amit Schendel
8 views•4 min read