GHSA-W2CH-4XGR-22WW: Missing Authorization in Vikunja Task Relation Deletion
Vulnerability ID: GHSA-W2CH-4XGR-22WW
CVSS Score: 5.3
Published: 2026-10-09
An authorization bypass vulnerability in Vikunja versions prior to v2.6.0 permits authenticated users to delete relationships between tasks across project boundaries without requiring read or write authorization for the target related task.
TL;DR
In Vikunja versions prior to 2.6.0, deleting a task relation only verifies access permissions for the source task. An authenticated user can unlink tasks in unauthorized or private projects.
Technical Details
- CWE ID: CWE-862 (Missing Authorization)
- CVSS v3.1 Score: 5.3 (Medium)
- Attack Vector: Network (Unauthenticated: No, Authenticated: Yes)
- Impact: Integrity (Unauthorized relation removal)
- Exploit Status: None / No public weaponized exploit
- CISA KEV Status: Not Listed
Affected Systems
- Vikunja API (< 2.6.0)
- Vikunja Frontend (< 2.6.0)
-
Vikunja: < 2.6.0 (Fixed in:
2.6.0)
Code Analysis
Commit: 077dc4d
Fix relation deletion checking read access to the other task
Mitigation Strategies
- Upgrade Vikunja server instance to version v2.6.0 or higher.
- Restrict user registration on sensitive Vikunja deployments to trusted staff.
- Monitor API request logs for repeated task relation deletion calls across project boundaries.
Remediation Steps:
- Pull the latest Vikunja Docker image or download the v2.6.0 release binary.
- Restart the Vikunja server service to apply the update.
- Verify the application version in the system settings or admin panel.
References
- GitHub Security Advisory GHSA-W2CH-4XGR-22WW
- Vikunja PR #3688 Fix Task Relation Authorization
- Vikunja Commit 077dc4de79ce6f1ab59215a2c7bf9b30423685f2
- Vikunja v2.6.0 Release Notes
Read the full report for GHSA-W2CH-4XGR-22WW on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)