GHSA-phph-c358-5mwm

Suggest an improvement
Source
https://github.com/advisories/GHSA-phph-c358-5mwm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-phph-c358-5mwm/GHSA-phph-c358-5mwm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-phph-c358-5mwm
Withdrawn
2026-10-09T20:51:46Z
Published
2026-09-15T18:32:30Z
Modified
2026-10-09T21:00:07Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts)
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-9rg3-v78m-26q8. This link is maintained to preserve external references.

Original Description

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without proper permission verification.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-09T20:51:46Z",
    "nvd_published_at": "2026-09-15T16:17:55Z",
    "severity": "MODERATE"
}
References

Affected packages

Go / code.vikunja.io/api

Package

Name
code.vikunja.io/api
View open source insights on deps.dev
Purl
pkg:golang/code.vikunja.io/api

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0
Last Affected
2.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-phph-c358-5mwm/GHSA-phph-c358-5mwm.json"