mediumVulnerability

GHSA-fmmf-xq98-g327

## Summary A project member with Write permission can delete an admin-tier link share on that project. The deletion authorization check reads the permission from an object populated only with URL IDs, rather than from the stored share. Its zero value is Read, so the check falls through to project Write permission instead of requiring Admin. ## Details Affected endpoints: - `DELETE /api/v1/projects/{project}/shares/{share}` - `DELETE /api/v2/projects/{project}/shares/{share}` Older v1 releases used `/lists/{list}/shares/{share}` before lists were renamed to projects. In `pkg/routes/api/v2/link_sharing.go:156`, the delete handler passes `&models.LinkSharing{ID: in.ID, ProjectID: in.ProjectID}` to `handler.DoDelete`. The v1 generic handler likewise binds the URL IDs without loading the stored share. `pkg/web/handler/core.go:185` calls `CanDelete` before `Delete`. `LinkSharing.CanDelete` delegates to `canDoLinkShare` in `pkg/models/link_sharing_permissions.go`. That helper loads the project but does not load the link share, then evaluates: ```go if share.Permission == PermissionAdmin { return l.IsAdmin(s, a) } return l.CanWrite(s, a) ``` On deletion, `share.Permission` is its Go zero value, `PermissionRead` (0), even when the stored share grants `PermissionAdmin` (2). A Write member therefore passes authorization. `LinkSharing.Delete` subsequently deletes by share ID and project ID without checking the stored permission. Create uses the requested permission and correctly rejects Write members creating admin shares. Share listing and by-ID reads are admin-gated in current main. There is no HTTP update route for link shares. Read-only members and link-share principals are rejected on deletion. ## Affected versions and verification The admin-tier check was introduced in commit `56dbb564eae83f2453efd1049f55e9d099b5d346`, first included in v0.13, without loading the stored share on deletion. The affected range established by this review is `>= 0.13.0, <= 2.6.

Properties

ghsa_id
GHSA-fmmf-xq98-g327
severity
medium
summary
Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check
last_source
GitHub Advisory Database
cve_id
GHSA-fmmf-xq98-g327
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T20:57:47Z
source_url
https://github.com/advisories/GHSA-fmmf-xq98-g327
ghsa_updated
2026-10-09T20:57:48Z

Related Entities (4)

VULNERABLE_TO (1)

←[Software]go/code.vikunja.io/api

AFFECTS (1)

→[Software]go/code.vikunja.io/api

HAS_WEAKNESS (1)

→[Weakness]Incorrect Authorization

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-fmmf-xq98-g327 — Ninja Signal Threat Intelligence | Ninja Signal