PatchSiren

go-vikunja CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL go-vikunja CVE published 2026-08-02

CVE-2026-68582

The CVE-2026-68582 record describes a Broken Object Level Authorization (BOLA) vulnerability in Vikunja versions >= 0.24.0 and <= 2.3.0. The task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks) does not verify caller authorization for requested project views. This allows link-share token holders to access kanban bucket records across tenants, including bucket titles and created_by [truncated]

HIGH go-vikunja CVE published 2026-08-02

CVE-2026-68581

Vikunja versions 0.22.0 through 2.3.0 have an authentication bypass vulnerability due to improper validation of principal types in API token management. An attacker can obtain a target user's numeric ID via authenticated user search, create link shares on an attacker-writable project, and use the resulting link-share JWT to manipulate the target user's API tokens. This CVE record was published on 2026-08- [truncated]