CVE-2026-33473

medium

Description

Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any user that has enabled 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.2.1 patches the issue.

References

https://vikunja.io/changelog/vikunja-v2.2.2-was-released

https://vikunja.io/changelog/vikunja-v2.2.0-was-released

https://github.com/go-vikunja/vikunja/security/advisories/GHSA-p747-qc5p-773r

Details

Source: Mitre, NVD

Published: 2026-03-24

Updated: 2026-03-24

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.7

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Severity: Medium