GHSA-FPRF-R6RV-XG99: GHSA-FPRF-R6RV-XG99: Cross-Tenant Task Position Recalculation in Vikunja
GHSA-FPRF-R6RV-XG99: Cross-Tenant Task Position Recalculation in Vikunja Vulnerability ID: GHSA-FPRF-R6RV-XG99 CVSS Score: 6.5 Published: 2026-10-09 A cross-tenant boundary breach vulnerability in Vikunja allows an
GHSA-FPRF-R6RV-XG99: Cross-Tenant Task Position Recalculation in Vikunja
Vulnerability ID: GHSA-FPRF-R6RV-XG99
CVSS Score: 6.5
Published: 2026-10-09
A cross-tenant boundary breach vulnerability in Vikunja allows an authenticated user to trigger global task position recalculations across all tenant instances by creating a saved filter with an empty filter string payload.
TL;DR
Creating a saved filter with an empty filter string in Vikunja triggers task position recalculation across all database tenants, resulting in cross-tenant data integrity corruption and potential service degradation.
β οΈ Exploit Status: POC
Technical Details
- Vulnerability ID: GHSA-FPRF-R6RV-XG99
- CWE ID: CWE-284 (Improper Access Control)
- Attack Vector: Network / Remote
- Privileges Required: Low (Authenticated User)
- Impact: Cross-Tenant State Modification / Integrity Breach
- Exploit Status: PoC Method Documented
Affected Systems
- Vikunja multi-tenant deployments
Mitigation Strategies
- Enforce mandatory tenant isolation scoping predicates (
tenant_id = ?) across all database queries regardless of filter parameter state. - Validate saved filter request payloads to reject empty string values prior to database processing.
- Implement database row-level security (RLS) to prevent cross-tenant record modifications at the storage layer.
Remediation Steps:
- Upgrade the Vikunja instance to the latest fixed version provided by upstream maintainers.
- Audit existing saved filter entries in the database to remove invalid empty filter records.
- Implement perimeter API request validation rules to block requests containing
"filter": ""payloads.
References
Read the full report for GHSA-FPRF-R6RV-XG99 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.