GHSA-8wvg-r2j4-3737: Infoleak
Summary TaskAssginee.ReadAll returns assignee user objects without blanking the Email field, disclosing assignee email addresses to any read-only project member. Every sibling path that returns user objects obfuscates the email; this one does not.
Details pkg/models/taskassignees.go (~lines 306-344) does Select("users.") and returns the result directly. User.Email is json:"email,omitempty", so a non-empty value always serializes. The endpoint gates on task.CanRead, so a read-only member passes. Sibling paths blank the field: pkg/models/tasks.go:530, pkg/models/projectusers.go:216, pkg/models/teams.go:177, pkg/models/labeltask.go:312, pkg/models/taskattachment.go:511. The omission here reads as an oversight, not a decision.
The same file's getRawTaskAssigneesForTasks (~line 56) also selects users. but is safe because its only caller (addAssigneesToTasks) blanks the email afterwards.
PoC (verified at runtime against v2.5.0, v1 and v2) GET /api/v1/tasks/{id}/assignees (reader with permission:0) -> [{"id":37,"username":"...","email":"assignee+SECRET@example.test", ...}] Same leak on GET /api/v2/tasks/{id}/assignees (routes through the identical model method). Contrast: GET /api/v1/projects/{id}/projectusers and the project task-embed both return the same users with no email.
Impact Disclosure of assignees' email addresses to users who should only see usernames. Read-only.
Fix Blank Email on each returned user in TaskAssginee.ReadAll before returning, matching the sibling paths. Covers v1 and v2 at once.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/code.vikunja.io/apito a version that resolves this vulnerability.Fixed in 2.6.0 - Configuration
Blank the Email field on each returned assignee user before returning the result, for both v1 and v2 task-assignee endpoints.
TaskAssginee.ReadAll Email