Security: go-vikunja/vikunja
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Link-share principal-type confusion enables cross-account team removal, bot takeover, and roster disclosureGHSA-32r8-5843-4qw2 published
Aug 4, 2026 by kolaenteHigh -
Link-share principal ID collision allows cross-account API token issuance and managementGHSA-vvcv-vpph-h844 published
Jul 19, 2026 by kolaenteHigh -
Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA)GHSA-rj9j-8772-4h6c published
Jul 19, 2026 by kolaenteHigh -
OIDC email-fallback account linking ignores email_verified, enabling local-account takeoverGHSA-xv7q-fvmc-jx96 published
Jul 19, 2026 by kolaenteHigh -
Plaintext storage of password-reset/email-confirm tokens in database enables account takeover on DB read accessGHSA-r6w9-259g-gwrv published
Jul 19, 2026 by kolaenteHigh -
Project duplication bypasses write-permission check on the target parent projectGHSA-f27p-pw2p-9pr4 published
Jul 19, 2026 by kolaenteModerate -
Authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignmentGHSA-569v-q83c-3j3g published
Jul 19, 2026 by kolaenteModerate -
Scoped API token can mint unrestricted OAuth session credentialsGHSA-v3p6-34mc-hj7v published
Jul 19, 2026 by kolaenteHigh -
Cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_idGHSA-5pg6-m483-7vrg published
Jul 19, 2026 by kolaenteHigh -
Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/apiGHSA-gg93-x632-9ccv published
Jul 19, 2026 by kolaenteHigh
Learn more about advisories related to go-vikunja/vikunja in the GitHub Advisory Database