Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 1 min read

GHSA-FPRF-R6RV-XG99: GHSA-FPRF-R6RV-XG99: Cross-Tenant Task Position Recalculation in Vikunja

GHSA-FPRF-R6RV-XG99: Cross-Tenant Task Position Recalculation in Vikunja Vulnerability ID: GHSA-FPRF-R6RV-XG99 CVSS Score: 6.5 Published: 2026-10-09 A cross-tenant boundary breach vulnerability in Vikunja allows an

GHSA-FPRF-R6RV-XG99: Cross-Tenant Task Position Recalculation in Vikunja

Vulnerability ID: GHSA-FPRF-R6RV-XG99
CVSS Score: 6.5
Published: 2026-10-09

A cross-tenant boundary breach vulnerability in Vikunja allows an authenticated user to trigger global task position recalculations across all tenant instances by creating a saved filter with an empty filter string payload.

TL;DR

Creating a saved filter with an empty filter string in Vikunja triggers task position recalculation across all database tenants, resulting in cross-tenant data integrity corruption and potential service degradation.

⚠️ Exploit Status: POC

Technical Details

  • Vulnerability ID: GHSA-FPRF-R6RV-XG99
  • CWE ID: CWE-284 (Improper Access Control)
  • Attack Vector: Network / Remote
  • Privileges Required: Low (Authenticated User)
  • Impact: Cross-Tenant State Modification / Integrity Breach
  • Exploit Status: PoC Method Documented

Affected Systems

  • Vikunja multi-tenant deployments

Mitigation Strategies

  • Enforce mandatory tenant isolation scoping predicates (tenant_id = ?) across all database queries regardless of filter parameter state.
  • Validate saved filter request payloads to reject empty string values prior to database processing.
  • Implement database row-level security (RLS) to prevent cross-tenant record modifications at the storage layer.

Remediation Steps:

  1. Upgrade the Vikunja instance to the latest fixed version provided by upstream maintainers.
  2. Audit existing saved filter entries in the database to remove invalid empty filter records.
  3. Implement perimeter API request validation rules to block requests containing "filter": "" payloads.

References

Read the full report for GHSA-FPRF-R6RV-XG99 on our website for more details including interactive diagrams and full exploit analysis.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.