Skip to main content

Api: Vikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint

0
Medium
Published: 10/09/2026 (10/09/2026, 20:54:49 UTC)
Source: GCVE Database
Product: code.vikunja.io/api

Description

A vulnerability in the Vikunja API causes assignee email addresses to be disclosed to read-only project members via the task assignees endpoint. Unlike other endpoints that obfuscate user email addresses, this endpoint returns the email field unmasked. This issue affects versions prior to 2.6.0 and allows unauthorized disclosure of email addresses without additional privileges.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected software

Goghsa
code.vikunja.io/api
Affected versions
<2.6.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 22:46:18 UTC

Technical Analysis

The TaskAssginee.ReadAll method in Vikunja API returns user objects including the Email field without blanking it, unlike sibling endpoints that obfuscate email addresses. This results in disclosure of assignee email addresses to any user with read-only access to a project. The vulnerability was verified in versions v1, v2, and v2.5.0. The root cause is that the method selects all user fields and serializes the Email field if non-empty, without redacting it before returning the response. The endpoint enforces read permission but does not restrict email visibility. The fix involves blanking the Email field on each returned user in this method to align with other endpoints.

Potential Impact

Assignee email addresses are disclosed to users who have only read-only access to project tasks. This information disclosure could lead to privacy concerns or targeted phishing but does not allow modification or further access. The impact is limited to information disclosure of email addresses.

Mitigation Recommendations

A patch is available that blanks the Email field on each returned user in the TaskAssginee.ReadAll method before returning the response. This fix aligns with other endpoints and covers both API v1 and v2. Users should upgrade to version 2.6.0 or later where this issue is resolved.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-8wvg-r2j4-3737
Osv Schema Version
1.4.0
Ecosystems
["Go"]
Database Specific Severity
MODERATE
Cvss Version
4.0

Threat ID: 6ac96e3f2cdf04f65689a5df

Added to database: 10/09/2026, 22:44:15 UTC

Last enriched: 10/09/2026, 22:46:18 UTC

Last updated: 10/09/2026, 22:46:18 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses