Skip to main content

Api: Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants

0
Medium
Published: 10/09/2026 (10/09/2026, 20:57:38 UTC)
Source: GCVE Database
Product: code.vikunja.io/api

Description

In Vikunja v2.6.0, creating a saved filter with an empty filter string while the user has no accessible projects causes a task position recalculation that loses project scope and writes task position data across all tenants. This allows an authenticated user to write task position entries referencing tasks from other tenants, violating tenant data integrity and causing write amplification proportional to the instance size. The issue arises because the recalculation query executes without a project scope filter when no accessible projects exist, and the server writes position rows unconditionally. This flaw contradicts intended access controls and was confirmed with a proof-of-concept.

CVSS v3.1

Score 5.4medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Affected software

Goghsa
code.vikunja.io/api
Affected versions
>=1.0.0-rc0 <=2.6.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 22:45:41 UTC

Technical Analysis

Vikunja computes task ordering in a shared task_positions table keyed by task and project view. When a saved filter is created with an empty filter string and the requesting user has no accessible projects, the recalculation logic resets project scope to zero and injects the filter string. The subsequent search query loses its project scope filter due to zero accessible projects and an empty filter string, resulting in a full table scan of all tasks. The server then deletes and bulk-inserts task position rows for all tasks across four default views owned by the user, including tasks from other tenants. This leads to cross-tenant data integrity violations and write amplification. The issue is triggered by setting the user's default project ID to a project they cannot access and deleting their Inbox project, resulting in zero accessible projects. Neighboring code paths enforce project access checks, but this recalculation path lacks such gating, violating the invariant that position writes are scoped by project read access.

Potential Impact

An authenticated user can cause the server to write task position entries referencing tasks from other tenants, violating tenant data isolation and integrity. This write amplification scales with the total number of tasks in the instance, potentially impacting database performance and storage. Although the attacker cannot read the foreign tasks through normal API endpoints, the cross-tenant writes represent a serious integrity violation. There is no indication of direct confidentiality or availability impact beyond the write amplification and integrity breach.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid creating saved filters with empty filter strings when having no accessible projects. Additionally, administrators should monitor for unusual task_positions table growth or cross-tenant data anomalies. The vendor advisory or repository should be consulted for updates or official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-fprf-r6rv-xg99
Osv Schema Version
1.4.0
Ecosystems
["Go"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6ac96e3d2cdf04f65689a541

Added to database: 10/09/2026, 22:44:13 UTC

Last enriched: 10/09/2026, 22:45:41 UTC

Last updated: 10/09/2026, 22:45:41 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses