GHSA-8wvg-r2j4-3737: Infoleak

Published Oct 9, 2026
·
Updated

Summary TaskAssginee.ReadAll returns assignee user objects without blanking the Email field, disclosing assignee email addresses to any read-only project member. Every sibling path that returns user objects obfuscates the email; this one does not.

Details pkg/models/taskassignees.go (~lines 306-344) does Select("users.") and returns the result directly. User.Email is json:"email,omitempty", so a non-empty value always serializes. The endpoint gates on task.CanRead, so a read-only member passes. Sibling paths blank the field: pkg/models/tasks.go:530, pkg/models/projectusers.go:216, pkg/models/teams.go:177, pkg/models/labeltask.go:312, pkg/models/taskattachment.go:511. The omission here reads as an oversight, not a decision.

The same file's getRawTaskAssigneesForTasks (~line 56) also selects users. but is safe because its only caller (addAssigneesToTasks) blanks the email afterwards.

PoC (verified at runtime against v2.5.0, v1 and v2) GET /api/v1/tasks/{id}/assignees (reader with permission:0) -> [{"id":37,"username":"...","email":"assignee+SECRET@example.test", ...}] Same leak on GET /api/v2/tasks/{id}/assignees (routes through the identical model method). Contrast: GET /api/v1/projects/{id}/projectusers and the project task-embed both return the same users with no email.

Impact Disclosure of assignees' email addresses to users who should only see usernames. Read-only.

Fix Blank Email on each returned user in TaskAssginee.ReadAll before returning, matching the sibling paths. Covers v1 and v2 at once.

Affected Software

1 affected componentFixes available
go/code.vikunja.io/api<=2.5.0
2.6.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/code.vikunja.io/api to a version that resolves this vulnerability.

    Fixed in 2.6.0
  2. Configuration

    Blank the Email field on each returned assignee user before returning the result, for both v1 and v2 task-assignee endpoints.

    TaskAssginee.ReadAll Email

Event History

Oct 9, 2026
Advisory Published
via GitHub·08:54 PM
Data Sourced
via GitHub·08:54 PM
DescriptionWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203