Vikunja 是一个开源的自托管任务管理平台。从 0.21.0 到 2.4.0, 中的项目复制操作允许拥有源项目读取权限的已认证用户,将项目的副本放置到任意的目标父项目之下。 调用了一个未完全初始化(unhydrated)的 对象上的 ,该对象仅包含请求体中提供的 ,而不是调用 ,因此跳过了对目标父项目的写权限检查。普通的项目创建路径会强制进行该权限校验,但 接口未执行此检查,从而使得攻击者拥有的内容可以被注入到其他用户或团队的项目层级结构中。 该问题已在 2.4.0 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| go-vikunja | vikunja | >= 0.21.0, < 2.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| go-vikunja | vikunja | >= 0.21.0, < 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55065 | 8.1 HIGH | Vikunja: Improper Authorization and Authorization Bypass Through User-Controlled Key in co |
| CVE-2026-55066 | 7.1 HIGH | Vikunja: Cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id |
| CVE-2026-55067 | 5.0 MEDIUM | Vikunja: Authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-as |
| CVE-2026-55064 | 4.3 MEDIUM | Vikunja incomplete fix for CVE-2026-35595: Write-only user can detach shared project from |
No comments yet