Impact
The vulnerability allows an attacker to sign in as a legitimate local user by providing an OIDC token contains the target’s email address. Because the system never checks whether the email has been verified or requires the user’s password, any token from the configured provider can be used to hijack the session and obtain full access to the victim’s data. The flaw effectively grants full read/write privileges to the account holder without the victim’s consent.
Affected Systems
The issue affects Vikunja, the open‑source self‑hosted task management platform, in versions 1.0.0 through 2.3.0. The vendor is Go‑Vikunja and the product is Vikunja. The fix is included in release 2.4.0.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is considered a high risk. Exploitation does not rely on local access or password disclosure; an adversary only needs a valid token for the victim’s email, which can be acquired via phishing, compromised IdP credentials, or a legitimately signed token. The EPSS score is not available, but the absence of email verification makes this a serious threat. The vulnerability is not listed in CISA KEV at the time of writing.
OpenCVE Enrichment
Github GHSA