mediumCVSS 5.4Vulnerability

GHSA-pjr3-86v4-5p7w

## Description ### Summary In Vikunja v2.6.0 the project-permission engine resolves a user's effective permission on a project as the **MAX over the entire reachable project subtree**. As a result, when a user has been granted a **higher** permission on a parent project and the owner *explicitly* shares a **child** project with that same user at a **lower** permission (an intended down-restriction), the explicit lower grant is **silently ignored** and the user receives the higher, inherited permission on the child. A user who was deliberately restricted to **read-only** on a sensitive sub-project can therefore modify it, delete it, and re-share it (including granting other users admin) - none of which the owner intended. This is a behavior regression from v2.5.0, whose engine used "nearest-ancestor-grant-wins" semantics that honored the explicit child grant. ### Details Effective permissions are computed by a single recursive CTE in `pkg/models/project_access.go` (`getProjectAccessForUser`): ```sql WITH RECURSIVE grants (project_id, permission) AS ( SELECT project_id, MAX(permission) FROM ( SELECT id AS project_id, 2 AS permission FROM projects WHERE owner_id = ? UNION ALL SELECT project_id, permission FROM users_projects WHERE user_id = ? UNION ALL SELECT tp.project_id, tp.permission FROM team_projects tp INNER JOIN team_members tm ON tm.team_id = tp.team_id WHERE tm.user_id = ? ) direct_grants GROUP BY project_id ), tree (id, permission) AS ( SELECT p.id, g.permission FROM projects p INNER JOIN grants g ON g.project_id = p.id UNION SELECT p.id, t.permission FROM projects p INNER JOIN tree t ON p.parent_project_id = t.id ) SELECT id, MAX(permission) AS permission FROM tree GROUP BY id ``` For a parent `P` where the user has a direct ADMIN(2) grant and a child `C` (with `parent_project_id = P`) where the user has a direct READ(0) grant, the `tree` CTE produces the rows `(P,2)`, `(C,0)` (direct grant

Properties

severity
medium
summary
Vikunja: Explicit lower-permission share on a sub-project is silently overridden by an inherited parent permission (broken access control / privilege-management regression in v2.6.0)
cvss_score
5.4
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T20:57:44Z
source_url
https://github.com/advisories/GHSA-pjr3-86v4-5p7w
ghsa_updated
2026-10-09T20:57:45Z
ghsa_id
GHSA-pjr3-86v4-5p7w
last_source
GitHub Advisory Database
cve_id
GHSA-pjr3-86v4-5p7w
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true

Related Entities (5)

VULNERABLE_TO (1)

←[Software]go/code.vikunja.io/api

AFFECTS (1)

→[Software]go/code.vikunja.io/api

HAS_WEAKNESS (2)

→[Weakness]Improper Privilege Management
→[Weakness]Improper Access Control

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-pjr3-86v4-5p7w (CVSS 5.4) — Ninja Signal Threat Intelligence | Ninja Signal