GHSA-8wvg-r2j4-3737

Suggest an improvement
Source
https://github.com/advisories/GHSA-8wvg-r2j4-3737
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8wvg-r2j4-3737/GHSA-8wvg-r2j4-3737.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8wvg-r2j4-3737
Published
2026-10-09T20:54:49Z
Modified
2026-10-09T21:00:09Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Vikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint
Details

Summary

TaskAssginee.ReadAll returns assignee user objects without blanking the Email field, disclosing assignee email addresses to any read-only project member. Every sibling path that returns user objects obfuscates the email; this one does not.

Details

pkg/models/task_assignees.go (~lines 306-344) does Select("users.*") and returns the result directly. User.Email is json:"email,omitempty", so a non-empty value always serializes. The endpoint gates on task.CanRead, so a read-only member passes. Sibling paths blank the field: pkg/models/tasks.go:530, pkg/models/project_users.go:216, pkg/models/teams.go:177, pkg/models/label_task.go:312, pkg/models/task_attachment.go:511. The omission here reads as an oversight, not a decision.

The same file's getRawTaskAssigneesForTasks (~line 56) also selects users.* but is safe because its only caller (addAssigneesToTasks) blanks the email afterwards.

PoC (verified at runtime against v2.5.0, v1 and v2)

GET /api/v1/tasks/{id}/assignees   (reader with permission:0)
-> [{"id":37,"username":"...","email":"assignee+SECRET@example.test", ...}]

Same leak on GET /api/v2/tasks/{id}/assignees (routes through the identical model method). Contrast: GET /api/v1/projects/{id}/projectusers and the project task-embed both return the same users with no email.

Impact

Disclosure of assignees' email addresses to users who should only see usernames. Read-only.

Fix

Blank Email on each returned user in TaskAssginee.ReadAll before returning, matching the sibling paths. Covers v1 and v2 at once.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-09T20:54:49Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

Go / code.vikunja.io/api

Package

Name
code.vikunja.io/api
View open source insights on deps.dev
Purl
pkg:golang/code.vikunja.io/api

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.6.0

Database specific

last_known_affected_version_range
"<= 2.5.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8wvg-r2j4-3737/GHSA-8wvg-r2j4-3737.json"