GHSA-G38J-7V97-X298: Missing Authorization Check in Vikunja CalDAV Task Relation Creation
Vulnerability ID: GHSA-G38J-7V97-X298
CVSS Score: 6.5
Published: 2026-10-09
In Vikunja prior to version 2.6.0, relation creation via the CalDAV endpoint fails to invoke the TaskRelation.CanCreate authorization check. This missing access control allows an authenticated user to establish unauthorized relationships and perform write operations against any task, provided its unique identifier (UID) is known.
TL;DR
Vikunja's CalDAV engine omitted authorization checks when creating task relations, allowing authenticated users with a target task UID to create unauthorized linkages and modify restricted task structures.
Technical Details
- CWE Identifier: CWE-862 (Missing Authorization)
- Attack Vector: Network (CalDAV Endpoint)
- CVSS Score: 6.5 (Medium)
- EPSS Score: N/A (GHSA identifier without CVE mapping)
- Impact: Unauthorized Write / Relation Creation across tasks
- Exploit Status: No public weaponized exploit available
- CISA KEV Status: Not Listed
Affected Systems
- Vikunja backend installations prior to version 2.6.0 running CalDAV services
-
Vikunja: < 2.6.0 (Fixed in:
2.6.0)
Code Analysis
Commit: 077dc4d
Enforce TaskRelation authorization checks during CalDAV relation handling
Mitigation Strategies
- Upgrade the Vikunja backend deployment to version v2.6.0 or higher.
- Restrict network access to the CalDAV endpoint (/dav/...) via web application firewall or reverse proxy if patching cannot be immediately performed.
- Audit database task relations for unexpected cross-user or cross-project links established prior to patching.
Remediation Steps:
- Pull the latest Vikunja container image or binary release tagged v2.6.0 or later.
- Restart the Vikunja backend service to load the updated executable binaries.
- Inspect server logs for CalDAV request activity to ensure operational stability after patching.
References
- GitHub Security Advisory GHSA-G38J-7V97-X298
- Vikunja GitHub Repository
- Vikunja Pull Request #3688
- Fix Commit 077dc4de79ce6f1ab59215a2c7bf9b30423685f2
- Vikunja Release v2.6.0
Read the full report for GHSA-G38J-7V97-X298 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)