Impact
Vikunja releases up to 2.4.0 contain a principal‑type confusion flaw that treats LinkSharing principals with an identifier N as user principals when the user ID equals N in three permission checks that lack type guarding. An attacker who holds or can obtain a link‑share JWT can exploit ID collisions in the auto‑increment space to remove victim users from teams, enumerate and delete victim bot accounts, or read team rosters. The flaw allows privileged actions without proper authentication or authorization, effectively providing unauthorized access to sensitive resources.
Affected Systems
go‑vikunja's Vikunja application, version 2.4.0 and earlier. The vulnerability is present in all releases through 2.4.0. System administrators should check the published version numbers against the vendor list: any deployment of Vikunja prior to 2.4.1 is affected.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. Because the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog, the current exploitation risk appears uncertain, but the flaw's nature means an attacker with a link‑share JWT can perform destructive or exfiltration actions. Likely attack vector is remote API authentication via a crafted link‑share JWT, which requires sending a request to the system that holds the token. Successful exploitation would grant the attacker the same rights as a legitimate user or higher if the collision is with a privileged ID.
OpenCVE Enrichment