Api: Duplicate Advisory: Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA)
Description
Vikunja versions 0.24.0 through 2.3.0 have a broken object level authorization (BOLA) vulnerability in the task-collection API endpoint. This flaw allows holders of any project share link to read kanban bucket titles and user information (username, name, id) from other tenants across the instance. The vulnerability does not disclose task contents outside the share's own project. It also enables an existence oracle for project/view IDs. The issue is fixed in version 2.4.0.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in Vikunja's task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks) where the requested project view is loaded from the URL path without verifying the caller's authorization. While the task scope is limited to the share's own project for link-share token holders, the view parameter is attacker-controlled and not re-validated. This allows unauthorized reading of any tenant's kanban bucket records, including bucket titles and full created_by user objects (username, name, id) for every view in the instance. Additionally, the missing pre-authorization check creates a project/view-ID existence oracle via differing HTTP responses. Task contents themselves remain protected and are not disclosed. The vulnerability is fixed in Vikunja version 2.4.0.
Potential Impact
An attacker with a link-share token can enumerate and read kanban bucket metadata and user information across all tenants in the Vikunja instance, violating tenant data isolation. This exposure includes sensitive user identifiers but does not disclose task content. The existence oracle can aid attackers in mapping valid project/view IDs. This impacts confidentiality but not integrity or availability.
Mitigation Recommendations
Upgrade Vikunja to version 2.4.0 or later where this broken object level authorization vulnerability is fixed. No other mitigations are indicated. Patch status is confirmed by the vendor advisory stating the issue is fixed in 2.4.0.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p4r4-8cxw-pjx7
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Go"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6ac96e522cdf04f65689a7a8
Added to database: 10/09/2026, 22:44:34 UTC
Last enriched: 10/09/2026, 22:49:41 UTC
Last updated: 10/09/2026, 22:49:41 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.