Api: Vikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint
Description
A vulnerability in the Vikunja API causes assignee email addresses to be disclosed to read-only project members via the task assignees endpoint. Unlike other endpoints that obfuscate user email addresses, this endpoint returns the email field unmasked. This issue affects versions prior to 2.6.0 and allows unauthorized disclosure of email addresses without additional privileges.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The TaskAssginee.ReadAll method in Vikunja API returns user objects including the Email field without blanking it, unlike sibling endpoints that obfuscate email addresses. This results in disclosure of assignee email addresses to any user with read-only access to a project. The vulnerability was verified in versions v1, v2, and v2.5.0. The root cause is that the method selects all user fields and serializes the Email field if non-empty, without redacting it before returning the response. The endpoint enforces read permission but does not restrict email visibility. The fix involves blanking the Email field on each returned user in this method to align with other endpoints.
Potential Impact
Assignee email addresses are disclosed to users who have only read-only access to project tasks. This information disclosure could lead to privacy concerns or targeted phishing but does not allow modification or further access. The impact is limited to information disclosure of email addresses.
Mitigation Recommendations
A patch is available that blanks the Email field on each returned user in the TaskAssginee.ReadAll method before returning the response. This fix aligns with other endpoints and covers both API v1 and v2. Users should upgrade to version 2.6.0 or later where this issue is resolved.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8wvg-r2j4-3737
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6ac96e3f2cdf04f65689a5df
Added to database: 10/09/2026, 22:44:15 UTC
Last enriched: 10/09/2026, 22:46:18 UTC
Last updated: 10/09/2026, 22:46:18 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.