Beveiligingsadvies

CVE-2026-33676

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-24 15:35:37
Laatst bijgewerkt 2026-03-24 18:55:19
Toegewezen door GitHub_M
CVSS-score 6.5
Status PUBLISHED

Beschrijving

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tasks, it populates the `related_tasks` field with full task objects for all related tasks without checking whether the requesting user has read permission on those tasks' projects. An authenticated user who can read a task that has cross-project relations will receive full details (title, description, due dates, priority, percent completion, project ID, etc.) of tasks in projects they have no access to. Version 2.2.1 patches the issue.