Api: Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants
Description
In Vikunja v2.6.0, creating a saved filter with an empty filter string while the user has no accessible projects causes a task position recalculation that loses project scope and writes task position data across all tenants. This allows an authenticated user to write task position entries referencing tasks from other tenants, violating tenant data integrity and causing write amplification proportional to the instance size. The issue arises because the recalculation query executes without a project scope filter when no accessible projects exist, and the server writes position rows unconditionally. This flaw contradicts intended access controls and was confirmed with a proof-of-concept.
CVSS v3.1
Score 5.4medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Vikunja computes task ordering in a shared task_positions table keyed by task and project view. When a saved filter is created with an empty filter string and the requesting user has no accessible projects, the recalculation logic resets project scope to zero and injects the filter string. The subsequent search query loses its project scope filter due to zero accessible projects and an empty filter string, resulting in a full table scan of all tasks. The server then deletes and bulk-inserts task position rows for all tasks across four default views owned by the user, including tasks from other tenants. This leads to cross-tenant data integrity violations and write amplification. The issue is triggered by setting the user's default project ID to a project they cannot access and deleting their Inbox project, resulting in zero accessible projects. Neighboring code paths enforce project access checks, but this recalculation path lacks such gating, violating the invariant that position writes are scoped by project read access.
Potential Impact
An authenticated user can cause the server to write task position entries referencing tasks from other tenants, violating tenant data isolation and integrity. This write amplification scales with the total number of tasks in the instance, potentially impacting database performance and storage. Although the attacker cannot read the foreign tasks through normal API endpoints, the cross-tenant writes represent a serious integrity violation. There is no indication of direct confidentiality or availability impact beyond the write amplification and integrity breach.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid creating saved filters with empty filter strings when having no accessible projects. Additionally, administrators should monitor for unusual task_positions table growth or cross-tenant data anomalies. The vendor advisory or repository should be consulted for updates or official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fprf-r6rv-xg99
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ac96e3d2cdf04f65689a541
Added to database: 10/09/2026, 22:44:13 UTC
Last enriched: 10/09/2026, 22:45:41 UTC
Last updated: 10/09/2026, 22:45:41 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.