Vikunja 是一个开源的自托管任务管理平台。在 1.0.0 至 2.3.0 版本中,当管理员为某个 OpenID Connect(OIDC)提供商启用 per-provider 的 选项时,Vikunja 会仅根据身份提供商(IdP)提供的 声明,将单点登录(SSO)登录关联到一个预先存在的本地(用户名+密码)账户。该回退机制从不检查 (或 Microsoft 特有的 )字段,也从不要求匹配账户的密码。如果攻击者能够从配置的 Issuer 处获取包含受害者邮箱的令牌,即可直接以该受害者身份登录,并建立完整会话,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| go-vikunja | vikunja | >= 1.0.0, < 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57458 | 8.1 HIGH | Vikunja: Scoped API token can mint unrestricted OAuth session credentials |
| CVE-2026-62376 | 8.1 HIGH | Vikunja: Plaintext storage of password-reset/email-confirm tokens in database enables acco |
No comments yet