Vikunja是Vikunja开源的一个待办事项应用程序。 Vikunja 0.21.0至2.2.0之前版本存在代码注入漏洞,该漏洞源于Vikunja Desktop Electron包装器在主BrowserWindow中启用了nodeIntegration且未限制同窗口导航,可能导致攻击者通过用户生成内容中的链接使BrowserWindow导航至攻击者控制的源,进而执行具有完整Node.js访问权限的JavaScript,最终在受害者机器上执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| go-vikunja | vikunja | >= 0.21.0, < 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33316 | 8.1 HIGH | Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablem |
| CVE-2026-33678 | 8.1 HIGH | Vikunja has IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion |
| CVE-2026-33680 | 7.5 HIGH | Vikunja Vulnerable to Link Share Hash Disclosure via ReadAll Endpoint Enables Permission E |
| CVE-2026-33474 | 6.5 MEDIUM | Vikunja Affected by DoS via Image Preview Generation |
| CVE-2026-33677 | 6.5 MEDIUM | Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API |
| CVE-2026-33676 | 6.5 MEDIUM | Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorizatio |
| CVE-2026-33675 | 6.4 MEDIUM | Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Int |
| CVE-2026-33679 | 6.4 MEDIUM | Vikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections |
| CVE-2026-33473 | 5.7 MEDIUM | Vikunja has TOTP Reuse During Validity Window |
| CVE-2026-33315 | Vikunja has a 2FA Bypass via Caldav Basic Auth | |
| CVE-2026-33313 | Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments | |
| CVE-2026-33335 | Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openEx | |
| CVE-2026-33334 | Vikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegratio | |
| CVE-2026-33668 | Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and O | |
| CVE-2026-33700 | Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Projec |
No comments yet