mediumVulnerability

GHSA-3hc7-r24j-rpwc

### Summary Vikunja lets a task in one project have a subtask that lives in a different project. When listing a project's tasks, an option pulls in those subtasks (?expand%5B%5D=subtasks). The main listing is correctly filtered to the projects the caller can access, but the subtask expansion is not: it returns the linked subtasks regardless of whether the caller has any access to the project they belong to. So a member with read-only access to one project can read the full content of tasks in other, private projects, any task that is a (recursive) subtask of a task the member is allowed to see. ### Details Subtasks can cross project boundaries; a task in an accessible project can be linked as the parent of a subtask that lives in a private project. Creating that link requires access to both tasks, so the link itself is set up legitimately by someone who has it. The problem is what happens afterwards, on read. When a task list is requested with subtask expansion, the server takes the tasks the caller is allowed to see and walks their subtask relations recursively to fetch the linked tasks. That fetch doesn't apply the access-control filter the main listing use, it returns every linked task by ID, with no check on whether the caller can access the project it belongs to. Because the walk is recursive, it also returns the entire subtree beneath each linked task. The effect is a cross-project read. A read-only member of project P who has no access at all to a private project Q can retrieve Q's tasks, full objects, including title, description, dates, assignees, labels, and attachment metadata, as long as some task in Q is linked as a subtask under a task in P. The links persist after access changes, so a former collaborator who has been removed from Q, but still has read access to P, keeps this read channel into Q. The fix is to apply the same project-access filter to the expanded subtasks that the main listing already applies, so only subtasks in projects the calle

Properties

ghsa_id
GHSA-3hc7-r24j-rpwc
severity
medium
summary
Vikunja: Cross-project task disclosure through subtask expansion
last_source
GitHub Advisory Database
cve_id
GHSA-3hc7-r24j-rpwc
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T20:54:46Z
source_url
https://github.com/advisories/GHSA-3hc7-r24j-rpwc
ghsa_updated
2026-10-09T20:54:47Z

Related Entities (5)

VULNERABLE_TO (1)

←[Software]go/code.vikunja.io/api

AFFECTS (1)

→[Software]go/code.vikunja.io/api

HAS_WEAKNESS (2)

→[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
→[Weakness]Missing Authorization

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-3hc7-r24j-rpwc — Ninja Signal Threat Intelligence | Ninja Signal