πŸ” CVE Alert

CVE-2026-55067

MEDIUM 5.0

Vikunja: Authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment

CVSS Score
5.0
EPSS Score
0.0%
EPSS Percentile
0th

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by Bucket.Update in pkg/models/kanban.go. The permission check validates that the bucket currently belongs to the URL project and view but does not validate the body selected destination view, allowing any authenticated user to relocate an attacker-owned bucket into another tenant’s Kanban view. The injected bucket retains attacker-controlled content and ownership, enabling cross-tenant defacement. This issue is fixed in version 2.4.0.

CWE CWE-639
Vendor go-vikunja
Product vikunja
Published Aug 28, 2026
Last Updated Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for go-vikunja vikunja

Be the first to know when new medium vulnerabilities affecting go-vikunja vikunja are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

go-vikunja / vikunja
< 2.4.0

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/go-vikunja/vikunja/security/advisories/GHSA-569v-q83c-3j3g github.com: https://github.com/go-vikunja/vikunja/pull/3239 github.com: https://github.com/go-vikunja/vikunja/commit/b31d606b8879ebe98fbb2ac5d8b3066b86f59868 github.com: https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0