Impact
The vulnerability allows an attacker with a limited API token to request additional data through the expand query parameter in task read endpoints. The authorization logic does not validate the token scope for expanded fields, enabling access to comments, reactions, and time entries that the token normally should not reveal. This flaw results in data exposure of sensitive task details without requiring elevated privileges.
Affected Systems
Vikunja, versions prior to 2.6.0 (go‑vikunja:vikunja).
Risk and Exploitability
The flaw has a CVSS score of 5.3, indicating moderate severity. The EPSS score of < 1% reflects a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers must possess a valid API token with limited scope but can manipulate the expand parameter to bypass scope restrictions. This bypass does not grant new privileges or authentication, but it does expose otherwise protected data such as task comments, reactions, and time entries. The attack vector is through standard API calls to task read endpoints, which is likely exploitable by anyone who can interact with the API using an authorized token.
OpenCVE Enrichment