Api: Vikunja: CalDAV relation creation bypasses TaskRelation.CanCreate, allowing an unauthorized write into any task by known UID
Description
A vulnerability in Vikunja's CalDAV API allows an attacker to create task relations without proper permission checks. This bypass enables unauthorized writes to any task by specifying its UID, even in projects the attacker cannot access. The issue arises because the CalDAV relation creation path does not enforce the TaskRelation.CanCreate permission check, unlike the REST API. Task UIDs are exposed via CalDAV to users who previously had read access, enabling removed collaborators to exploit this. The flaw also facilitates cross-project subtask relation creation, which can lead to further information disclosure. A fix is available that routes CalDAV relation creation through the proper permission checks and scopes UID lookups to accessible projects.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Vikunja CalDAV API's task relation creation functionality bypasses the TaskRelation.CanCreate permission check enforced by the REST API. Specifically, the CalDAV handler uses an unscoped UID lookup to identify related tasks and directly creates relations without verifying if the user has permission to create them. Since task UIDs are exposed to anyone who had read access to the project via CalDAV, an attacker who knows a task's UID can attach a relation to that task, even if they no longer have access to the project containing it. This unauthorized write capability allows attackers to create subtask or parent relations across projects, violating access controls and enabling further cross-project disclosure issues. The vulnerability was verified in Vikunja version 2.5.0 and affects all versions prior to 2.6.0. The recommended fix is to enforce permission checks on CalDAV relation creation and restrict UID lookups to projects accessible by the caller.
Potential Impact
This vulnerability results in broken access control allowing unauthorized users to write task relations to any task by UID, including tasks in projects they do not have access to. Attackers can create subtask or parent relations arbitrarily, potentially polluting task relations and enabling cross-project disclosure issues. While reading the related task's contents still requires separate disclosure vulnerabilities, this flaw enables unauthorized write operations that violate project boundaries and data integrity.
Mitigation Recommendations
A patch is available that fixes this vulnerability by routing CalDAV relation creation through the TaskRelation.CanCreate permission check and scoping UID lookups to projects accessible by the caller. Users should upgrade to Vikunja version 2.6.0 or later to remediate this issue. Until patched, users should consider restricting CalDAV access to trusted users only, especially those who previously had project read access.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-g38j-7v97-x298
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6ac96e432cdf04f65689a67d
Added to database: 10/09/2026, 22:44:19 UTC
Last enriched: 10/09/2026, 22:46:27 UTC
Last updated: 10/09/2026, 22:46:27 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.