highVulnerability

CVE-2026-91985

## Summary A user who has only read permission on a project can call the single link-share read endpoint and receive the share's `hash` field — the secret credential that the anonymous `POST /shares/{share}/auth` endpoint exchanges for a link-share JWT carrying the share's permission (read / read-write / admin). A read-only member can therefore mint a write- or admin-level token for the project and perform writes they are not entitled to, while their own user token is correctly refused. This is the remaining variant of the link-share hash disclosure class: GHSA-8hp8-9fhr-pfm9 fixed the list endpoint (ReadAll now requires project admin) but the single-read endpoint's gate was never aligned. Verified on Vikunja 2.5.0; the weak gate has existed since the endpoint, so earlier versions are likely affected too. ## Details Affected endpoints (both verified with a complete chain): - v1: `GET /api/v1/projects/{project}/shares/{share}` - v2: `GET /api/v2/projects/{project}/shares/{share}` Permission gate: `LinkSharing.CanRead` (`pkg/models/link_sharing_permissions.go`) delegates to `project.CanRead(s, a)` — i.e. any user with read access to the project passes. The response serializes the `hash` field (`pkg/models/link_sharing.go`, field tag `json:"hash"`), which is the share's bearer credential. The share `password` field is correctly cleared before returning, but the hash is not restricted. Inconsistent with the sibling list endpoint `GET /projects/{project}/shares` (`LinkSharing.ReadAll`, `pkg/models/link_sharing.go:243-256`), which requires `project.IsAdmin` — the protection level the project chose when the class was fixed for the list endpoint in 2.3.0 (GHSA-8hp8). The v1 and v2 APIs share the same model-level gate (the v2 `handler.DoReadOne` wrappers call the same `CanRead`), so both surfaces are affected. Impact chain: hash -> `POST /api/v1/shares/{hash}/auth` (unauthenticated by design) -> link-share JWT at the share's permission level -> full API access at that

Properties

ghsa_id
GHSA-qfwc-vx6f-3g6g
summary
Vikunja: Read-only project members can obtain any link share's access hash via the single-share read endpoint (v1 and v2) and escalate to the share's permission level
severity
high
last_source
GitHub Advisory Database
cve_id
CVE-2026-91985
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
false
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T20:51:29Z
source_url
https://github.com/advisories/GHSA-qfwc-vx6f-3g6g
ghsa_updated
2026-10-09T20:51:30Z

Related Entities (6)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]go/code.vikunja.io/api

AFFECTS (1)

→[Software]go/code.vikunja.io/api

HAS_WEAKNESS (3)

→[Weakness]Missing Authorization
→[Weakness]Authorization Bypass Through User-Controlled Key
→[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-91985 — Ninja Signal Threat Intelligence | Ninja Signal