GHSA-fmmf-xq98-g327
## Summary A project member with Write permission can delete an admin-tier link share on that project. The deletion authorization check reads the permission from an object populated only with URL IDs, rather than from the stored share. Its zero value is Read, so the check falls through to project Write permission instead of requiring Admin. ## Details Affected endpoints: - `DELETE /api/v1/projects/{project}/shares/{share}` - `DELETE /api/v2/projects/{project}/shares/{share}` Older v1 releases used `/lists/{list}/shares/{share}` before lists were renamed to projects. In `pkg/routes/api/v2/link_sharing.go:156`, the delete handler passes `&models.LinkSharing{ID: in.ID, ProjectID: in.ProjectID}` to `handler.DoDelete`. The v1 generic handler likewise binds the URL IDs without loading the stored share. `pkg/web/handler/core.go:185` calls `CanDelete` before `Delete`. `LinkSharing.CanDelete` delegates to `canDoLinkShare` in `pkg/models/link_sharing_permissions.go`. That helper loads the project but does not load the link share, then evaluates: ```go if share.Permission == PermissionAdmin { return l.IsAdmin(s, a) } return l.CanWrite(s, a) ``` On deletion, `share.Permission` is its Go zero value, `PermissionRead` (0), even when the stored share grants `PermissionAdmin` (2). A Write member therefore passes authorization. `LinkSharing.Delete` subsequently deletes by share ID and project ID without checking the stored permission. Create uses the requested permission and correctly rejects Write members creating admin shares. Share listing and by-ID reads are admin-gated in current main. There is no HTTP update route for link shares. Read-only members and link-share principals are rejected on deletion. ## Affected versions and verification The admin-tier check was introduced in commit `56dbb564eae83f2453efd1049f55e9d099b5d346`, first included in v0.13, without loading the stored share on deletion. The affected range established by this review is `>= 0.13.0, <= 2.6.
Properties
- ghsa_id
- GHSA-fmmf-xq98-g327
- severity
- medium
- summary
- Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-fmmf-xq98-g327
- signal_observed_at
- 2026-10-10T02:17:04+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-10-10T02:17:04+00:00
- ghsa_published
- 2026-10-09T20:57:47Z
- source_url
- https://github.com/advisories/GHSA-fmmf-xq98-g327
- ghsa_updated
- 2026-10-09T20:57:48Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph