Security: go-vikunja/vikunja
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDORGHSA-2pv8-4c52-mf8j published
Mar 23, 2026 by kolaenteCritical -
Any frontend XSS escalates to Remote Code Execution due to nodeIntegration in Vikunja DesktopGHSA-xh67-63q3-hf7g published
Mar 20, 2026 by kolaenteHigh -
Arbitrary local application invocation via unvalidated shell.openExternal in Vikunja DesktopGHSA-6q44-85gc-cjvf published
Mar 20, 2026 by kolaenteHigh -
Remote Code Execution via same-window navigation in Vikunja DesktopGHSA-83w9-9jf6-88vf published
Mar 20, 2026 by kolaenteCritical -
IDOR in Task Comments Allows Reading Arbitrary CommentsGHSA-mr3j-p26x-72x4 published
Mar 20, 2026 by kolaenteModerate -
Read-only users can delete project background images via broken object-level authorizationGHSA-564f-wx8x-878h published
Mar 20, 2026 by kolaenteModerate -
2FA Bypass via Caldav Basic AuthGHSA-47cr-f226-r4pq published
Mar 20, 2026 by kolaenteModerate -
Improper Access Control Enables Bypass of Administrator-Imposed Account DisablementGHSA-vq4q-79hh-q767 published
Mar 20, 2026 by kolaenteHigh -
TOTP Reuse During Validity WindowGHSA-p747-qc5p-773r published
Mar 20, 2026 by kolaenteModerate -
DoS via Image Preview GenerationGHSA-wc83-79hj-hpmq published
Mar 20, 2026 by kolaenteHigh