highVulnerability

GHSA-m687-p538-r5hp

## Summary Vikunja ships with `cors.origins` defaulting to `http://127.0.0.1:*` and `http://localhost:*`, and sends `Access-Control-Allow-Credentials: true`, so a page served from any port on the user's own machine may make credentialed cross-origin requests to the API and read the responses. The mandatory `service.publicurl` is appended to that default list rather than replacing it, so a fully configured production deployment still trusts every localhost origin. Combined with the token refresh endpoint, which authenticates with the `vikunja_refresh_token` cookie and returns a bearer JWT in the response body, one `fetch()` from such a page yields a working access token for whoever is logged in, and from there the whole account. ## Vulnerability Details `cors.enable` defaults to true and `cors.origins` defaults to the two localhost wildcards: https://github.com/go-vikunja/vikunja/blob/a881ac39eecd07575a5aede8e74727c28d5fd578/pkg/config/config.go#L495-L497 The middleware is registered with `AllowCredentials: true` and an `UnsafeAllowOriginFunc` that implements the port wildcard through `matchCORSOrigin`, since Echo v5 will not accept a wildcard port itself: https://github.com/go-vikunja/vikunja/blob/a881ac39eecd07575a5aede8e74727c28d5fd578/pkg/routes/routes.go#L263-L281 The detail that turns a development convenience into a production exposure is the last line of configuration handling. Enabling CORS without a public URL is a fatal error, so every deployment sets one, and that value is *appended* to the origin list rather than substituted for it: https://github.com/go-vikunja/vikunja/blob/a881ac39eecd07575a5aede8e74727c28d5fd578/pkg/config/config.go#L828-L830 An operator who configures nothing but their own hostname therefore ends up allowing three origins with credentials: their site, and any port on `localhost` and `127.0.0.1`. There is no supported configuration in which the localhost entries are quietly dropped, and nothing in the logs distinguishes the i

Properties

ghsa_id
GHSA-m687-p538-r5hp
severity
high
summary
Vikunja: Permissive Cross-domain Security Policy trusts every localhost origin which should not be trusted
last_source
GitHub Advisory Database
cve_id
GHSA-m687-p538-r5hp
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T20:57:50Z
source_url
https://github.com/advisories/GHSA-m687-p538-r5hp
ghsa_updated
2026-10-09T20:57:52Z

Related Entities (4)

VULNERABLE_TO (1)

←[Software]go/code.vikunja.io/api

AFFECTS (1)

→[Software]go/code.vikunja.io/api

HAS_WEAKNESS (1)

→[Weakness]Permissive Cross-domain Security Policy with Untrusted Domains

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-m687-p538-r5hp — Ninja Signal Threat Intelligence | Ninja Signal