SCA: security update for code.vikunja.io/api (GHSA-rj9j-8772-4h6c)

critical Tenable Self-Hosted Container Security Plugin ID 474069

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability
in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads
the requested project view from the URL path without verifying the caller is authorized for it. For a
link-share token holder, the task scope is pinned to the share's own project, but the view is taken from
the attacker-controlled path and never re-validated. As a result, a holder of any project share link can
read any other tenant's kanban bucket records — bucket titles and the full created_by user object
(username, name, id) — for every view in the instance. The same missing pre-authorization view load also
creates a project/view-ID existence oracle (404 vs. non-404) usable by link shares and ordinary
authenticated users. Task contents remain constrained to the share's own project and are not disclosed.
Fixed in 2.4.0. (CVE-2026-68582)

Solution

Update the code.vikunja.io/api library and its related packages to version 2.4.0 or later.

See Also

https://github.com/advisories/GHSA-rj9j-8772-4h6c

Plugin Details

Severity: Critical

ID: 474069

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/10/2026

Updated: 10/10/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-68582

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 8/2/2026

Reference Information

CVE: CVE-2026-68582