GHSA-8wvg-r2j4-3737: Email Address Exposure in Vikunja Task Assignees API
Vulnerability ID: GHSA-8WVG-R2J4-3737
CVSS Score: 4.3
Published: 2026-10-09
An information disclosure vulnerability in Vikunja allows authenticated users with read access to a task to expose private email addresses of assigned users through the API task assignees endpoint due to an unmasked database query.
TL;DR
Vikunja versions prior to 2.6.0 disclose private user email addresses to any authenticated user with read permissions on a task due to over-broad SQL model population in the task assignees endpoint.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-200
- CVSSv3 Score: 4.3 (Medium)
- Attack Vector: Network (Authenticated)
- Impact: Information Disclosure (PII / Private Email)
- Exploit Status: Proof-of-Concept
- Patched Version: v2.6.0
Affected Systems
- code.vikunja.io/api < 2.6.0
- github.com/go-vikunja/vikunja < v2.6.0
-
Vikunja: < 2.6.0 (Fixed in:
v2.6.0)
Code Analysis
Commit: 0855e13
fix(tasks): hide assignee email addresses
Mitigation Strategies
- Upgrade Vikunja instance to v2.6.0 or higher
- Restrict project sharing permissions with external untrusted accounts
- Deploy WAF rules to sanitize email fields in response objects
Remediation Steps:
- Fetch release tag v2.6.0 or later from official repository sources
- Rebuild or update the container image / application binary
- Restart the Vikunja service and verify application version via API health check
References
- GitHub Security Advisory GHSA-8wvg-r2j4-3737
- Vikunja PR #3688: fix(tasks): hide assignee email addresses
- Vikunja Release v2.6.0
- Patch diff for PR #3688
Read the full report for GHSA-8WVG-R2J4-3737 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)