DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-8WVG-R2J4-3737: GHSA-8wvg-r2j4-3737: Email Address Exposure in Vikunja Task Assignees API

GHSA-8wvg-r2j4-3737: Email Address Exposure in Vikunja Task Assignees API

Vulnerability ID: GHSA-8WVG-R2J4-3737
CVSS Score: 4.3
Published: 2026-10-09

An information disclosure vulnerability in Vikunja allows authenticated users with read access to a task to expose private email addresses of assigned users through the API task assignees endpoint due to an unmasked database query.

TL;DR

Vikunja versions prior to 2.6.0 disclose private user email addresses to any authenticated user with read permissions on a task due to over-broad SQL model population in the task assignees endpoint.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-200
  • CVSSv3 Score: 4.3 (Medium)
  • Attack Vector: Network (Authenticated)
  • Impact: Information Disclosure (PII / Private Email)
  • Exploit Status: Proof-of-Concept
  • Patched Version: v2.6.0

Affected Systems

  • code.vikunja.io/api < 2.6.0
  • github.com/go-vikunja/vikunja < v2.6.0
  • Vikunja: < 2.6.0 (Fixed in: v2.6.0)

Code Analysis

Commit: 0855e13

fix(tasks): hide assignee email addresses

Mitigation Strategies

  • Upgrade Vikunja instance to v2.6.0 or higher
  • Restrict project sharing permissions with external untrusted accounts
  • Deploy WAF rules to sanitize email fields in response objects

Remediation Steps:

  1. Fetch release tag v2.6.0 or later from official repository sources
  2. Rebuild or update the container image / application binary
  3. Restart the Vikunja service and verify application version via API health check

References


Read the full report for GHSA-8WVG-R2J4-3737 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)