GHSA-4HV6-XC92-J86G: GHSA-4HV6-XC92-J86G: Insufficient Session Expiration in Vikunja WebSocket Authentication Pipeline
GHSA-4HV6-XC92-J86G: Insufficient Session Expiration in Vikunja WebSocket Authentication Pipeline Vulnerability ID: GHSA-4HV6-XC92-J86G CVSS Score: 6.5 Published: 2026-10-09 Vikunja versions 2.3.0 through 2.6.0 cont
GHSA-4HV6-XC92-J86G: Insufficient Session Expiration in Vikunja WebSocket Authentication Pipeline
Vulnerability ID: GHSA-4HV6-XC92-J86G
CVSS Score: 6.5
Published: 2026-10-09
Vikunja versions 2.3.0 through 2.6.0 contain an insufficient session expiration vulnerability (CWE-613) within the WebSocket authentication handler. Although Vikunja enforces server-side session tracking and revocation for REST API routes, the WebSocket handshake handler validates cryptographic JWT signatures without querying the database session state. Consequently, revoked JWT tokens can establish new real-time WebSocket connections, and existing connections persist after session revocation.
TL;DR
Vikunja's WebSocket authentication pipeline skips database session state validation, allowing revoked JWT tokens to establish new real-time event streams and permitting existing connections to leak data indefinitely post-revocation.
β οΈ Exploit Status: POC
Technical Details
- CWE ID: CWE-613
- Attack Vector: Network (Authenticated WS Handshake with Revoked Token)
- CVSS v3.1 Score: 6.5 (Medium)
- Impact: Information Disclosure via Real-Time Server-Pushed Data Stream
- Exploit Status: Proof of Concept Available
- CISA KEV Status: Not Listed
- Affected Component: pkg/websocket/connection.go & pkg/modules/auth/auth.go
Affected Systems
- Vikunja Server API (
code.vikunja.io/api) -
Vikunja: >= 2.3.0, <= 2.6.0 (Fixed in:
Not reported)
Mitigation Strategies
- Enforce database session ID (sid) validation inside the WebSocket authentication handler prior to connection upgrades.
- Implement real-time connection termination signals in the WebSocket hub triggered by session deletion events.
- Reduce JWT token lifetimes to minimize the window during which unvalidated tokens can initiate WebSocket handshakes.
Remediation Steps:
- Modify pkg/websocket/connection.go to parse the sid claim from incoming JWT tokens.
- Query the active sessions table in the database to verify the sid exists before granting WebSocket protocol upgrade.
- Attach an event listener to session revocation routines (e.g., DeleteUserSession and DeleteAllUserSessions) that sends termination signals to active WebSocket connections matching the revoked session ID.
- Deploy reverse proxy rules to restrict maximum WebSocket connection duration and enforce period re-authentication.
References
- GitHub Security Advisory GHSA-4hv6-xc92-j86g
- GitHub Advisory Database Entry
- Vikunja Source Code Repository
Read the full report for GHSA-4HV6-XC92-J86G on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.