GHSA-xv7q-fvmc-jx96

Suggest an improvement
Source
https://github.com/advisories/GHSA-xv7q-fvmc-jx96
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-xv7q-fvmc-jx96/GHSA-xv7q-fvmc-jx96.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xv7q-fvmc-jx96
Aliases
  • CVE-2026-62367
Published
2026-10-09T20:49:06Z
Modified
2026-10-09T21:00:16Z
Severity
  • 7.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover
Details

Summary

With the per-provider OIDC emailfallback option enabled, Vikunja links an SSO login to a pre-existing local (username+password) account using only the email claim — no email_verified (or Microsoft xms_edov) check and no password check, on the unauthenticated callback. An attacker who can make the configured issuer emit a token bearing a victim's email logs in as that victim with a full session and no victim interaction (the nOAuth / Grafana CVE-2023-3128 class). The 2.3.0 fix for GHSA-8jvc-mcx6-r4cg added a TOTP gate, not an email_verified gate, so users without TOTP remain exposed.

Details

References are pkg/modules/auth/openid/openid.go at HEAD. Identity is first resolved on the immutable (issuer, subject) pair (openid.go:428). On a subject miss with emailfallback on, fallbackSearchUsers adds an email-only lookup against local accounts:

// openid.go:413
searches = append(searches, &user.User{Issuer: user.IssuerLocal, Email: cl.Email})

getUser resolves this via s.Get(), which ANDs non-zero fields -> WHERE issuer='local' AND email=?. Local users always have Issuer="local" (user_create.go:38), so the lookup matches any local account by email alone; getOrCreateUser returns it and the caller mints a session — the password is never read. The claims struct has no email_verified field (openid.go:80) and getClaims never consults one; a repo-wide grep for email_verified/xms_edov returns nothing. The code already warns about this at openid.go:388 ("Discouraged for untrusted providers where someone can set email without verification") — but enforces nothing.

Impact

Unauthenticated takeover of any existing local account (read/write/delete its projects, tasks, attachments, shares), bypassing the password. Scope notes: only issuer='local' accounts are matched (not pure-SSO users); the attacker's sub is not bound to the victim record, but the attack is repeatable; TOTP users are protected by the 2.3.0 enforceTOTPIfRequired gate (openid.go:250), non-TOTP users are not.

Preconditions

  1. Admin enabled emailfallback: true (defaults false — a default install is unaffected).
  2. The configured issuer lets the attacker assert the victim's unverified email: a self-service IdP (Keycloak/Authentik/Auth0/Dex with editable email), a mixed federation, or a multi-tenant Entra /common app. iss/aud are pinned, but the attacker controls email, not the issuer.
  3. The victim has a local account.

Not reachable against a single-tenant IdP that verifies email and disallows self-set addresses.

Recommended Fix

Add email_verified to the claims struct and require it true on the email-fallback branch before linking to a local account; reject when absent/false. For Entra also require xms_edov and pin multi-tenant configs to an allowed-tenant list. Fail closed on an email collision not backed by a verified email from a trusted single-tenant issuer rather than silently logging the caller in.

Database specific
{
    "cwe_ids": [
        "CWE-287",
        "CWE-290",
        "CWE-345"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-09T20:49:06Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

Go / code.vikunja.io/api

Package

Name
code.vikunja.io/api
View open source insights on deps.dev
Purl
pkg:golang/code.vikunja.io/api

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0
Fixed
2.4.0

Database specific

last_known_affected_version_range
"<= 2.3.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-xv7q-fvmc-jx96/GHSA-xv7q-fvmc-jx96.json"