Oct 10, 2026·5 min read·4 visits
Vikunja's CalDAV engine omitted authorization checks when creating task relations, allowing authenticated users with a target task UID to create unauthorized linkages and modify restricted task structures.
In Vikunja prior to version 2.6.0, relation creation via the CalDAV endpoint fails to invoke the TaskRelation.CanCreate authorization check. This missing access control allows an authenticated user to establish unauthorized relationships and perform write operations against any task, provided its unique identifier (UID) is known.
Vikunja is an open-source, self-hosted task management platform that integrates support for the CalDAV standard, allowing synchronization between task records and external calendar clients. CalDAV processing enables clients to parse, create, update, and manage task hierarchies and dependencies over standard HTTP methods.
During processing of incoming CalDAV requests that establish or mutate task relations, the application server omitted calling the core authorization routine TaskRelation.CanCreate. Consequently, permission evaluation was completely bypassed during relation establishment via CalDAV synchronization.
This flaw allows any authenticated account or entity capable of making CalDAV requests to target tasks outside their authorized scope. By specifying the target task's unique identifier (UID), an attacker can inject task relations, alter parent/child hierarchies, and achieve unauthorized write capabilities on protected resources.
The fundamental flaw stems from inconsistent authorization enforcement across protocol handlers. While traditional REST API handlers in Vikunja consistently execute TaskRelation.CanCreate prior to database modifications, the CalDAV endpoint handler implemented a separate code path that lacked explicit access check invocations.
When a CalDAV client transmits an updated event or VTODO object containing cross-task references, the CalDAV parser extracts the relational identifiers and forwards them to internal persistence functions. The handler assumed that authorization had been established during parent object retrieval, failing to independently validate whether the requesting user possessed write access to the target relation endpoint.
Because TaskRelation.CanCreate validates ownership, shared list permissions, and organization-level roles, omitting this invocation completely negated the multi-tenant access boundaries within shared Vikunja deployments.
In vulnerable versions, the CalDAV task processing pipeline handled task relations by directly constructing and saving TaskRelation instances without invoking security policies. The following code flow illustrates the missing validation check during relation initialization:
// Unpatched relation processing path in CalDAV handler
func (h *CalDAVHandler) handleTaskRelations(ctx context.Context, rel *models.TaskRelation) error {
// Bypassed: rel.CanCreate(ctx, user) check missing
return models.CreateTaskRelation(ctx, rel)
}To resolve this vulnerability in version 2.6.0, the codebase was updated to explicitly invoke the CanCreate policy method prior to relation persistence, ensuring that user identity and task access rights are evaluated against security boundaries:
// Patched relation processing path in CalDAV handler
func (h *CalDAVHandler) handleTaskRelations(ctx context.Context, rel *models.TaskRelation, user *models.User) error {
// Explicitly validate authorization using TaskRelation.CanCreate
canCreate, err := rel.CanCreate(ctx, user)
if err != nil || !canCreate {
return ErrUnauthorizedRelationCreation
}
return models.CreateTaskRelation(ctx, rel)
}The patch introduced in PR #3688 enforces strict validation before committing relational links. Security auditing indicates that this fix effectively seals the bypass for CalDAV workflows without breaking compliant calendar synchronization.
Exploitation requires two prerequisites: network access to the Vikunja CalDAV interface (/dav/...) with valid user credentials, and knowledge of the target task's unique identifier (UID).
An attacker constructs a crafted CalDAV request containing a relation definition (such as a parent-child or dependency mapping) linking their own task to the target task UID. Upon receiving the request, the CalDAV engine executes the relation creation routine.
Because the backend omits TaskRelation.CanCreate, the server establishes the link regardless of whether the user possesses write permissions for the target task. This enables unauthorized modification of task metadata, unauthorized task linking, and potential operational disruption across shared workspace environments.
The security impact of GHSA-G38J-7V97-X298 is categorized under Broken Access Control (CWE-285 / CWE-862). The primary vulnerability vector allows authenticated low-privileged users to modify data structures belonging to other users or organizations in a multi-tenant environment.
While this vulnerability does not directly grant remote code execution or arbitrary file access, it weakens the security guarantees of Vikunja's authorization model. Unauthorized relation creation can cause data corruption, workflow manipulation, and information leakage if relational metadata exposes internal project structures.
The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium severity, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Active exploitation in the wild has not been publicly observed.
System administrators must upgrade their Vikunja deployment to version 2.6.0 or higher. Version 2.6.0 includes the updated authorization checks within the CalDAV handler stack.
> [!NOTE]
> If immediate upgrading is not feasible, administrators can mitigate exposure by disabling or restricting network access to the CalDAV sync endpoints (/dav/...) via reverse proxy configuration rules.
To detect potential historical exploitation prior to patching, database administrators should audit the task_relations table for anomalous task relationships created via CalDAV user accounts, specifically cross-project linkages where the creating user lacked edit rights on both target tasks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
Vikunja Vikunja | < 2.6.0 | 2.6.0 |
| Attribute | Detail |
|---|---|
| CWE Identifier | CWE-862 (Missing Authorization) |
| Attack Vector | Network (CalDAV Endpoint) |
| CVSS Score | 6.5 (Medium) |
| EPSS Score | N/A (GHSA identifier without CVE mapping) |
| Impact | Unauthorized Write / Relation Creation across tasks |
| Exploit Status | No public weaponized exploit available |
| CISA KEV Status | Not Listed |
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
An information disclosure vulnerability in Contao CMS allows unauthenticated site visitors to view protected page titles, URLs, and text excerpts through search queries when protected page indexing is disabled after previously being enabled.
A cross-project information disclosure vulnerability in Vikunja allows authenticated users with read access to one project to view private task details from unauthorized projects via subtask expansion parameters.
An information disclosure vulnerability in Vikunja allows authenticated users with read access to a task to expose private email addresses of assigned users through the API task assignees endpoint due to an unmasked database query.
An authorization bypass vulnerability in Vikunja versions prior to v2.6.0 permits authenticated users to delete relationships between tasks across project boundaries without requiring read or write authorization for the target related task.
A path traversal vulnerability in Shiny for Python (posit-dev/py-shiny) versions 1.4.0 through 1.6.3 allows unauthenticated remote attackers to read arbitrary files and traverse directories via crafted _state_id_ query parameters.
A Stored Cross-Site Scripting vulnerability in @tinacms/web-components prior to version 0.2.1 allows low-privileged content authors to execute arbitrary JavaScript code in the context of website visitors via unsanitized URL attributes in custom Markdown rendering components.