Impact
Vikunja versions prior to 2.6.0 fail to verify that the project_view_id supplied in task-position requests actually belongs to the same project as the task. Because the project_view_id is supplied by the attacker, the vulnerability is a CWE‑639 type of authorization bypass. An authenticated attacker can send POST or PUT requests to the task‑position endpoint, inserting or altering rows that associate tenant. This enables unauthorized modification of project views and can expose sensitive data across tenant boundaries.
Affected Systems
The flaw affects all deployments of Vikunja running any release before 2.6.0. No other vendors, products, or versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 and EPSS score of less than 1% indicate a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The attack requires that the attacker be authenticated to the instance, so the vector is internal. Once authenticated, the attacker can exploit the missing project_view_id validation to add or modify task positions in views that belong to other tenants, potentially leaking or corrupting data.
OpenCVE Enrichment