GHSA-g38j-7v97-x298: Go/code.vikunja.io/api vulnerability

Published Oct 9, 2026
·
Updated

Summary Creating a task relation over CalDAV does not run the TaskRelation.CanCreate permission check that the REST API enforces. An attacker can attach a relation to any task whose UID they know, including tasks in projects they have no access to. The identical operation over REST is correctly refused with 403.

Details persistRelations (pkg/routes/caldav/listStorageProvider.go, ~line 986) resolves the related task with an unscoped UID lookup (models.GetTaskSimpleByUUID) and calls rel.Create(s, a) directly, with no CanCreate check. pkg/caldav/parsing.go maps RELATED-TO;RELTYPE=CHILD to RelationKindSubtask. Because the CalDAV path never invokes the model's permission method, an authenticated user can create a subtask/parent relation between a task they own and an arbitrary victim task identified only by its UID.

Task UIDs are json:"-" (never exposed over REST) but are exposed over CalDAV to anyone who has ever had read access to the containing project. Revoking that access does not unlearn the UID, so the realistic attacker is a removed collaborator.

This write primitive also feeds the cross-project subtask-disclosure issue (GHSA-3hc7-r24j-rpwc): it lets an attacker create the very cross-project subtask edge that read path leaks across, removing that finding's "the attacker cannot create one to a project they can't access" precondition.

A secondary effect of the same unchecked path: the createDummy branch can Create a task unchecked when the referenced UID does not resolve.

PoC (verified at runtime against v2.5.0, commit c775a6c8) Baseline control — REST refuses: PUT /api/v1/tasks/{attackerTask}/relations (attacker JWT) {"taskid":{attackerTask},"othertaskid":{victimTask},"relationkind":"subtask"} -> HTTP 403 Forbidden Exploit — CalDAV succeeds: PUT /dav/projects/{attackerProject}/{attackerTaskUID}.ics (BasicAuth attacker) BEGIN:VCALENDAR VERSION:2.0 BEGIN:VTODO UID:{attackerTaskUID} RELATED-TO;RELTYPE=CHILD:{victimTaskUID} END:VTODO END:VCALENDAR -> HTTP 201 Result: a taskrelations row is written with taskid={victimTask}, relationkind=parenttask, createdbyid={attacker} — a persisted, attacker-attributable write onto a task in a project the attacker cannot access.

Impact Broken access control (missing authorization) on relation creation. An attacker can pollute the relation set of arbitrary tasks by UID and create the cross-project edges that enable subtask disclosure. Read of the related task's contents still requires the separate disclosure path; this finding is the unauthorized write.

Fix Route CalDAV relation creation through TaskRelation.CanCreate, and scope the UID lookup to projects the caller can access.

Affected Software

1 affected componentFixes available
go/code.vikunja.io/api<=2.5.0
2.6.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/code.vikunja.io/api to a version that resolves this vulnerability.

    Fixed in 2.6.0
  2. Compensating control

    In CalDAV relation creation, route creation through TaskRelation.CanCreate and scope the related-task UID lookup to projects the caller can access.

Event History

Oct 9, 2026
Advisory Published
via GitHub·08:54 PM
Data Sourced
via GitHub·08:54 PM
DescriptionWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203