mediumVulnerability

CVE-2026-91982

### Summary Once a user has TOTP enabled, the API still hands back the raw shared secret to anyone holding that account's access token. Reading it doesn't ask for the password, even though disabling TOTP does. So a stolen token, an XSS, or a browser left open is enough to copy the second factor into your own authenticator and keep generating valid codes indefinitely. ### Details `GET /api/v1/user/settings/totp` returns the full TOTP object, including the secret field and the otpauth:// provisioning URL. `GET /api/v1/user/settings/totp/qrcode` renders the same secret as a QR image. Neither requires re-authentication, the access token alone is enough. This is inconsistent with the rest of the flow: `POST /api/v1/user/settings/totp/disable` calls CheckUserPassword before it will turn TOTP off. So the destructive action is gated behind the password, but reading out the secret that backs the second factor isn't. There's also no reason for the secret to be readable at all once enrollment is finished, the client only needs it during setup. The fix is to stop returning secret/url/the QR code once enabled is true (only expose them during the enrollment window). Requiring the password on the read, like disable already does, would also be reasonable. ### PoC The attacker needs the victim's access token, from an XSS, a leaked/stolen token, or an unlocked session. TOTP must already be enabled on the account. 1. With the victim's bearer token, call: ``` GET /api/v1/user/settings/totp Authorization: Bearer <victim_token> ``` The response contains the shared secret and the otpauth:// URL: ``` {"secret": "<base32 secret>", "enabled": true, "url": "otpauth://totp/..."} ``` 2. Paste that secret (or scan `/api/v1/user/settings/totp/qrcode`) into any authenticator app. 3. It now produces the same 6-digit codes as the victim's device. Nothing is logged and the victim gets no notification. ### Impact This defeats the purpose of the second factor. 2FA is supposed to survive exactly t

Properties

ghsa_id
GHSA-88f6-4rjv-x774
severity
medium
summary
Vikunja: TOTP secret is readable after enrollment, no step-up auth
last_source
GitHub Advisory Database
cve_id
CVE-2026-91982
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
false
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T20:51:17Z
source_url
https://github.com/advisories/GHSA-88f6-4rjv-x774
ghsa_updated
2026-10-09T20:51:19Z

Related Entities (5)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]go/code.vikunja.io/api

AFFECTS (1)

→[Software]go/code.vikunja.io/api

HAS_WEAKNESS (2)

→[Weakness]Cleartext Storage of Sensitive Information
→[Weakness]Insufficiently Protected Credentials

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-91982 — Ninja Signal Threat Intelligence | Ninja Signal