Impact
The vulnerability stems from insufficient validation of team membership when a project is shared. Authorized users can supply arbitrary team identifiers to the project teams endpoint and retrieve the complete roster for that team, including member names and administrator status. This flaw allows an attacker to infer the existence of all teams and their composition, thereby compromising confidentiality and potentially facilitating further social engineering or privilege escalation.
Affected Systems
The impact applies to the open‑source project management application "vikunja" from the vendor go‑vikunja. All releases prior to version 2.6.0 are affected, as they lack the access checks that restrict team enumeration based on project permissions.
Risk and Exploitability
The assigned CVSS score of 5.3 reflects a moderate risk; the EPSS score of < 1% indicates a low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must first authenticate to the system, but once authenticated they can repeatedly query the endpoint to enumerate any team. Because the exploitation does not require advanced privileges or complex payloads, the likelihood of real‑world abuse is moderate, especially in organizations where many teams are defined.
OpenCVE Enrichment