GHSA-2pv8-4c52-mf8j
CRITICALTwo independently-exploitable authorization flaws in Vikunja can be chained to allow an unauthenticated attacker to download and delete every file attachment across all projects in a Vikunja instance. The ReadAll endpoint for link shares exposes share hashes (including admin-level shares) to any user with read access, enabling permission escalation. The task attachment ReadOne/GetTaskAttachment en
- Affected
- >=0, <2.2.1
- Fixed in
- 2.2.1
- Weakness
- CWE-639
- Published
- 2026-03-26
- Source
- osv