CVE-2026-55066
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket
CVSS
7.1
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 28 ago 2026 · Última mod.: 28 ago 2026 · CWE-639
Sin historial EPSS suficiente todavía.
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket.go authorizes only the project, view, and bucket from the URL. updateTaskBucket then calls Task.ReadOne without a separate task permission check, returns the victim task contents, and can update the task done state when the attacker chooses a done bucket. Because task identifiers are global sequential values, an authenticated user can enumerate cross-tenant tasks and modify their completion metadata through both the v1 and v2 routes that share this model. This issue is fixed in version 2.4.0.
- github.comhttps://github.com/go-vikunja/vikunja/commit/36cdc2ce2be0b8ccc74227d178b92047d59cd65f
- github.comhttps://github.com/go-vikunja/vikunja/pull/3239
- github.comhttps://github.com/go-vikunja/vikunja/releases/tag/v2.4.0
- github.comhttps://github.com/go-vikunja/vikunja/security/advisories/GHSA-5pg6-m483-7vrg