GHSA-ccgq-fx7h-2v4cMediumCVSS 4.3

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position...

Published
September 15, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (1)

📋 Description

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST or PUT task-position endpoints.

🔗 References (4)