Impact
The vulnerability resides in the task‑collection endpoint of Vikunja. It allows anyone possessing a link‑share token to request a project view that is not owned by the share, bypassing the authorization check. This results in disclosure of other tenants’ kanban bucket titles and the complete creator metadata for every view that exists on the instance. The actual task contents are restricted to the shared project and are not exposed.
Affected Systems
Vikunja, provided by go‑vikunja, from version 0.24.0 through 2.3.0 are affected. The issue is tracked in the GitHub advisories for that product.
Risk and Exploitability
At a CVSS score of 9.3, the flaw is high in severity. The absence of an EPSS score means there is no publicly available estimate of exploitation likelihood. The vulnerability is not listed in CISA's KEV catalog. An attacker who obtains or guesses a link‑share token can exploit this flaw remotely, with no additional privileges, to read cross‑tenant metadata. No pre‑conditions beyond possession of a sharable token are needed.
OpenCVE Enrichment