GHSA-g38j-7v97-x298
### Summary Creating a task relation over CalDAV does not run the `TaskRelation.CanCreate` permission check that the REST API enforces. An attacker can attach a relation to any task whose UID they know, including tasks in projects they have no access to. The identical operation over REST is correctly refused with 403. ### Details `persistRelations` (`pkg/routes/caldav/listStorageProvider.go`, ~line 986) resolves the related task with an **unscoped** UID lookup (`models.GetTaskSimpleByUUID`) and calls `rel.Create(s, a)` directly, with no `CanCreate` check. `pkg/caldav/parsing.go` maps `RELATED-TO;RELTYPE=CHILD` to `RelationKindSubtask`. Because the CalDAV path never invokes the model's permission method, an authenticated user can create a subtask/parent relation between a task they own and an arbitrary victim task identified only by its UID. Task UIDs are `json:"-"` (never exposed over REST) but are exposed over CalDAV to anyone who has ever had read access to the containing project. Revoking that access does not unlearn the UID, so the realistic attacker is a removed collaborator. This write primitive also feeds the cross-project subtask-disclosure issue (GHSA-3hc7-r24j-rpwc): it lets an attacker create the very cross-project subtask edge that read path leaks across, removing that finding's "the attacker cannot create one to a project they can't access" precondition. A secondary effect of the same unchecked path: the `createDummy` branch can `Create` a task unchecked when the referenced UID does not resolve. ### PoC (verified at runtime against v2.5.0, commit c775a6c8) Baseline control — REST refuses: ``` PUT /api/v1/tasks/{attackerTask}/relations (attacker JWT) {"task_id":{attackerTask},"other_task_id":{victimTask},"relation_kind":"subtask"} -> HTTP 403 Forbidden ``` Exploit — CalDAV succeeds: ``` PUT /dav/projects/{attackerProject}/{attackerTaskUID}.ics (BasicAuth attacker) BEGIN:VCALENDAR VERSION:2.0 BEGIN:VTODO UID:{attackerTaskUID} RELATED-TO;RELTYPE=C
Properties
- ghsa_id
- GHSA-g38j-7v97-x298
- severity
- medium
- summary
- Vikunja: CalDAV relation creation bypasses TaskRelation.CanCreate, allowing an unauthorized write into any task by known UID
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-g38j-7v97-x298
- signal_observed_at
- 2026-10-10T02:17:04+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-10-10T02:17:04+00:00
- ghsa_published
- 2026-10-09T20:54:43Z
- source_url
- https://github.com/advisories/GHSA-g38j-7v97-x298
- ghsa_updated
- 2026-10-09T20:54:44Z
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph