Vulnerability Report: GO-2026-4847

Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.vikunja.io/api before v2.2.1.

For detailed information about this vulnerability, visit https://github.com/go-vikunja/vikunja/security/advisories/GHSA-8cmm-j6c4-rr8v or https://nvd.nist.gov/vuln/detail/CVE-2026-33676.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL