Impact
Vikunja before 2.6.0 fails to properly validate link‑share tokens in its v2 API user‑search endpoints. When an attacker has a read‑only share link, the projects endpoint returns all users with access to the shared project, and an attacker can then query the global search endpoint with the same token to confirm whether a specific username exists. This allows enumeration of active users on the instance, exposing sensitive user data solely through publicly available API calls.
Affected Systems
The vulnerability affects the open‑source project management application Vikunja, distributed by go‑vikunja. All releases prior to version 2.6.0 are vulnerable. The flaw is specific to the v2 API user‑search endpoints and applies to any instance that has share links enabled.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score of < 1% indicates a low probability of exploitation at present. Since the flaw relies on a read‑only share link, which may be freely available on public projects, the attacker can discover user enumerations by accessing the public API endpoints. The likely attack vector is the public API using a malicious request with a discovered share‑link token, which allows enumeration of usernames. The vulnerability is not listed in CISA's KEV catalog, so widespread exploitation is not currently documented, but the moderate CVSS score and the ease of using share links make it a potential risk for organizations that publicly share projects.
OpenCVE Enrichment