DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-W2CH-4XGR-22WW: GHSA-W2CH-4XGR-22WW: Missing Authorization in Vikunja Task Relation Deletion

GHSA-W2CH-4XGR-22WW: Missing Authorization in Vikunja Task Relation Deletion

Vulnerability ID: GHSA-W2CH-4XGR-22WW
CVSS Score: 5.3
Published: 2026-10-09

An authorization bypass vulnerability in Vikunja versions prior to v2.6.0 permits authenticated users to delete relationships between tasks across project boundaries without requiring read or write authorization for the target related task.

TL;DR

In Vikunja versions prior to 2.6.0, deleting a task relation only verifies access permissions for the source task. An authenticated user can unlink tasks in unauthorized or private projects.


Technical Details

  • CWE ID: CWE-862 (Missing Authorization)
  • CVSS v3.1 Score: 5.3 (Medium)
  • Attack Vector: Network (Unauthenticated: No, Authenticated: Yes)
  • Impact: Integrity (Unauthorized relation removal)
  • Exploit Status: None / No public weaponized exploit
  • CISA KEV Status: Not Listed

Affected Systems

  • Vikunja API (< 2.6.0)
  • Vikunja Frontend (< 2.6.0)
  • Vikunja: < 2.6.0 (Fixed in: 2.6.0)

Code Analysis

Commit: 077dc4d

Fix relation deletion checking read access to the other task

Mitigation Strategies

  • Upgrade Vikunja server instance to version v2.6.0 or higher.
  • Restrict user registration on sensitive Vikunja deployments to trusted staff.
  • Monitor API request logs for repeated task relation deletion calls across project boundaries.

Remediation Steps:

  1. Pull the latest Vikunja Docker image or download the v2.6.0 release binary.
  2. Restart the Vikunja server service to apply the update.
  3. Verify the application version in the system settings or admin panel.

References


Read the full report for GHSA-W2CH-4XGR-22WW on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)