CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-G38J-7V97-X298

GHSA-G38J-7V97-X298: Missing Authorization Check in Vikunja CalDAV Task Relation Creation

Alon Barad
Alon Barad
Software Engineer

Oct 10, 2026·5 min read·4 visits

Executive Summary (TL;DR)

Vikunja's CalDAV engine omitted authorization checks when creating task relations, allowing authenticated users with a target task UID to create unauthorized linkages and modify restricted task structures.

In Vikunja prior to version 2.6.0, relation creation via the CalDAV endpoint fails to invoke the TaskRelation.CanCreate authorization check. This missing access control allows an authenticated user to establish unauthorized relationships and perform write operations against any task, provided its unique identifier (UID) is known.

Vulnerability Overview

Vikunja is an open-source, self-hosted task management platform that integrates support for the CalDAV standard, allowing synchronization between task records and external calendar clients. CalDAV processing enables clients to parse, create, update, and manage task hierarchies and dependencies over standard HTTP methods.

During processing of incoming CalDAV requests that establish or mutate task relations, the application server omitted calling the core authorization routine TaskRelation.CanCreate. Consequently, permission evaluation was completely bypassed during relation establishment via CalDAV synchronization.

This flaw allows any authenticated account or entity capable of making CalDAV requests to target tasks outside their authorized scope. By specifying the target task's unique identifier (UID), an attacker can inject task relations, alter parent/child hierarchies, and achieve unauthorized write capabilities on protected resources.

Root Cause Analysis

The fundamental flaw stems from inconsistent authorization enforcement across protocol handlers. While traditional REST API handlers in Vikunja consistently execute TaskRelation.CanCreate prior to database modifications, the CalDAV endpoint handler implemented a separate code path that lacked explicit access check invocations.

When a CalDAV client transmits an updated event or VTODO object containing cross-task references, the CalDAV parser extracts the relational identifiers and forwards them to internal persistence functions. The handler assumed that authorization had been established during parent object retrieval, failing to independently validate whether the requesting user possessed write access to the target relation endpoint.

Because TaskRelation.CanCreate validates ownership, shared list permissions, and organization-level roles, omitting this invocation completely negated the multi-tenant access boundaries within shared Vikunja deployments.

Code Analysis & Patch Inspection

In vulnerable versions, the CalDAV task processing pipeline handled task relations by directly constructing and saving TaskRelation instances without invoking security policies. The following code flow illustrates the missing validation check during relation initialization:

// Unpatched relation processing path in CalDAV handler
func (h *CalDAVHandler) handleTaskRelations(ctx context.Context, rel *models.TaskRelation) error {
    // Bypassed: rel.CanCreate(ctx, user) check missing
    return models.CreateTaskRelation(ctx, rel)
}

To resolve this vulnerability in version 2.6.0, the codebase was updated to explicitly invoke the CanCreate policy method prior to relation persistence, ensuring that user identity and task access rights are evaluated against security boundaries:

// Patched relation processing path in CalDAV handler
func (h *CalDAVHandler) handleTaskRelations(ctx context.Context, rel *models.TaskRelation, user *models.User) error {
    // Explicitly validate authorization using TaskRelation.CanCreate
    canCreate, err := rel.CanCreate(ctx, user)
    if err != nil || !canCreate {
        return ErrUnauthorizedRelationCreation
    }
    return models.CreateTaskRelation(ctx, rel)
}

The patch introduced in PR #3688 enforces strict validation before committing relational links. Security auditing indicates that this fix effectively seals the bypass for CalDAV workflows without breaking compliant calendar synchronization.

Exploitation Mechanics

Exploitation requires two prerequisites: network access to the Vikunja CalDAV interface (/dav/...) with valid user credentials, and knowledge of the target task's unique identifier (UID).

An attacker constructs a crafted CalDAV request containing a relation definition (such as a parent-child or dependency mapping) linking their own task to the target task UID. Upon receiving the request, the CalDAV engine executes the relation creation routine.

Because the backend omits TaskRelation.CanCreate, the server establishes the link regardless of whether the user possesses write permissions for the target task. This enables unauthorized modification of task metadata, unauthorized task linking, and potential operational disruption across shared workspace environments.

Impact & Risk Assessment

The security impact of GHSA-G38J-7V97-X298 is categorized under Broken Access Control (CWE-285 / CWE-862). The primary vulnerability vector allows authenticated low-privileged users to modify data structures belonging to other users or organizations in a multi-tenant environment.

While this vulnerability does not directly grant remote code execution or arbitrary file access, it weakens the security guarantees of Vikunja's authorization model. Unauthorized relation creation can cause data corruption, workflow manipulation, and information leakage if relational metadata exposes internal project structures.

The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium severity, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Active exploitation in the wild has not been publicly observed.

Remediation & Detection Guidance

System administrators must upgrade their Vikunja deployment to version 2.6.0 or higher. Version 2.6.0 includes the updated authorization checks within the CalDAV handler stack.

> [!NOTE] > If immediate upgrading is not feasible, administrators can mitigate exposure by disabling or restricting network access to the CalDAV sync endpoints (/dav/...) via reverse proxy configuration rules.

To detect potential historical exploitation prior to patching, database administrators should audit the task_relations table for anomalous task relationships created via CalDAV user accounts, specifically cross-project linkages where the creating user lacked edit rights on both target tasks.

Official Patches

VikunjaSecurity Fix Pull Request #3688
VikunjaFix Commit 077dc4de79ce6f1ab59215a2c7bf9b30423685f2

Fix Analysis (1)

Technical Appendix

CVSS Score
6.5/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Systems

Vikunja backend installations prior to version 2.6.0 running CalDAV services

Affected Versions Detail

Product
Affected Versions
Fixed Version
Vikunja
Vikunja
< 2.6.02.6.0
AttributeDetail
CWE IdentifierCWE-862 (Missing Authorization)
Attack VectorNetwork (CalDAV Endpoint)
CVSS Score6.5 (Medium)
EPSS ScoreN/A (GHSA identifier without CVE mapping)
ImpactUnauthorized Write / Relation Creation across tasks
Exploit StatusNo public weaponized exploit available
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-862
Missing Authorization

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

Vulnerability Timeline

Vulnerability identified in Vikunja CalDAV relation processing
2024-05-01
Pull Request #3688 merged to resolve authorization bypass
2024-05-15
Vikunja version 2.6.0 released containing fix
2024-05-20
GitHub Security Advisory GHSA-G38J-7V97-X298 published
2024-05-22

References & Sources

  • [1]GitHub Security Advisory GHSA-G38J-7V97-X298
  • [2]Vikunja GitHub Repository
  • [3]Vikunja Pull Request #3688
  • [4]Fix Commit 077dc4de79ce6f1ab59215a2c7bf9b30423685f2
  • [5]Vikunja Release v2.6.0

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•19 minutes ago•CVE-2026-107842
5.3

CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module

An information disclosure vulnerability in Contao CMS allows unauthenticated site visitors to view protected page titles, URLs, and text excerpts through search queries when protected page indexing is disabled after previously being enabled.

Amit Schendel
Amit Schendel
3 views•4 min read
•about 2 hours ago•GHSA-3HC7-R24J-RPWC
6.8

GHSA-3hc7-r24j-rpwc: Cross-Project Task Disclosure via Subtask Expansion in Vikunja

A cross-project information disclosure vulnerability in Vikunja allows authenticated users with read access to one project to view private task details from unauthorized projects via subtask expansion parameters.

Alon Barad
Alon Barad
6 views•5 min read
•about 3 hours ago•GHSA-8WVG-R2J4-3737
4.3

GHSA-8wvg-r2j4-3737: Email Address Exposure in Vikunja Task Assignees API

An information disclosure vulnerability in Vikunja allows authenticated users with read access to a task to expose private email addresses of assigned users through the API task assignees endpoint due to an unmasked database query.

Amit Schendel
Amit Schendel
6 views•5 min read
•about 4 hours ago•GHSA-W2CH-4XGR-22WW
5.3

GHSA-W2CH-4XGR-22WW: Missing Authorization in Vikunja Task Relation Deletion

An authorization bypass vulnerability in Vikunja versions prior to v2.6.0 permits authenticated users to delete relationships between tasks across project boundaries without requiring read or write authorization for the target related task.

Alon Barad
Alon Barad
6 views•5 min read
•about 5 hours ago•CVE-2026-108258
6.9

CVE-2026-108258: Path Traversal in Shiny for Python Bookmark Restoration

A path traversal vulnerability in Shiny for Python (posit-dev/py-shiny) versions 1.4.0 through 1.6.3 allows unauthenticated remote attackers to read arbitrary files and traverse directories via crafted _state_id_ query parameters.

Alon Barad
Alon Barad
5 views•4 min read
•about 6 hours ago•CVE-2026-108260
7.6

CVE-2026-108260: Stored Cross-Site Scripting (XSS) in @tinacms/web-components

A Stored Cross-Site Scripting vulnerability in @tinacms/web-components prior to version 0.2.1 allows low-privileged content authors to execute arbitrary JavaScript code in the context of website visitors via unsanitized URL attributes in custom Markdown rendering components.

Alon Barad
Alon Barad
5 views•5 min read