Security Advisory

CVE-2026-33676

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-24 15:35:37
Last updated 2026-03-24 18:55:19
Assigner GitHub_M
State PUBLISHED

Description

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tasks, it populates the `related_tasks` field with full task objects for all related tasks without checking whether the requesting user has read permission on those tasks projects. An authenticated user who can read a task that has cross-project relations will receive full details (title, description, due dates, priority, percent completion, project ID, etc.) of tasks in projects they have no access to. Version 2.2.1 patches the issue.