mediumVulnerability

GHSA-8wvg-r2j4-3737

### Summary `TaskAssginee.ReadAll` returns assignee user objects without blanking the `Email` field, disclosing assignee email addresses to any read-only project member. Every sibling path that returns user objects obfuscates the email; this one does not. ### Details `pkg/models/task_assignees.go` (~lines 306-344) does `Select("users.*")` and returns the result directly. `User.Email` is `json:"email,omitempty"`, so a non-empty value always serializes. The endpoint gates on `task.CanRead`, so a read-only member passes. Sibling paths blank the field: `pkg/models/tasks.go:530`, `pkg/models/project_users.go:216`, `pkg/models/teams.go:177`, `pkg/models/label_task.go:312`, `pkg/models/task_attachment.go:511`. The omission here reads as an oversight, not a decision. The same file's `getRawTaskAssigneesForTasks` (~line 56) also selects `users.*` but is safe because its only caller (`addAssigneesToTasks`) blanks the email afterwards. ### PoC (verified at runtime against v2.5.0, v1 and v2) ``` GET /api/v1/tasks/{id}/assignees (reader with permission:0) -> [{"id":37,"username":"...","email":"[email protected]", ...}] ``` Same leak on `GET /api/v2/tasks/{id}/assignees` (routes through the identical model method). Contrast: `GET /api/v1/projects/{id}/projectusers` and the project task-embed both return the same users with no email. ### Impact Disclosure of assignees' email addresses to users who should only see usernames. Read-only. ### Fix Blank `Email` on each returned user in `TaskAssginee.ReadAll` before returning, matching the sibling paths. Covers v1 and v2 at once.

Properties

ghsa_id
GHSA-8wvg-r2j4-3737
severity
medium
summary
Vikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint
last_source
GitHub Advisory Database
cve_id
GHSA-8wvg-r2j4-3737
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T20:54:49Z
source_url
https://github.com/advisories/GHSA-8wvg-r2j4-3737
ghsa_updated
2026-10-09T20:54:51Z

Related Entities (4)

VULNERABLE_TO (1)

←[Software]go/code.vikunja.io/api

AFFECTS (1)

→[Software]go/code.vikunja.io/api

HAS_WEAKNESS (1)

→[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-8wvg-r2j4-3737 — Ninja Signal Threat Intelligence | Ninja Signal