VYPR

Vikunja

by Go Vikunja

Source repositories

CVEs (2)

  • CVE-2026-68581Aug 2, 2026
    risk 0.00cvss epss 0.00

    Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a…

  • CVE-2026-56765Jul 10, 2026
    risk 0.00cvss epss 0.00

    Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task…