Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 1 min read

GHSA-G38J-7V97-X298: GHSA-G38J-7V97-X298: Missing Authorization Check in Vikunja CalDAV Task Relation Creation

GHSA-G38J-7V97-X298: Missing Authorization Check in Vikunja CalDAV Task Relation Creation Vulnerability ID: GHSA-G38J-7V97-X298 CVSS Score: 6.5 Published: 2026-10-09 In Vikunja prior to version 2.6.0, relation creat

GHSA-G38J-7V97-X298: Missing Authorization Check in Vikunja CalDAV Task Relation Creation

Vulnerability ID: GHSA-G38J-7V97-X298
CVSS Score: 6.5
Published: 2026-10-09

In Vikunja prior to version 2.6.0, relation creation via the CalDAV endpoint fails to invoke the TaskRelation.CanCreate authorization check. This missing access control allows an authenticated user to establish unauthorized relationships and perform write operations against any task, provided its unique identifier (UID) is known.

TL;DR

Vikunja's CalDAV engine omitted authorization checks when creating task relations, allowing authenticated users with a target task UID to create unauthorized linkages and modify restricted task structures.

Technical Details

  • CWE Identifier: CWE-862 (Missing Authorization)
  • Attack Vector: Network (CalDAV Endpoint)
  • CVSS Score: 6.5 (Medium)
  • EPSS Score: N/A (GHSA identifier without CVE mapping)
  • Impact: Unauthorized Write / Relation Creation across tasks
  • Exploit Status: No public weaponized exploit available
  • CISA KEV Status: Not Listed

Affected Systems

  • Vikunja backend installations prior to version 2.6.0 running CalDAV services
  • Vikunja: < 2.6.0 (Fixed in: 2.6.0)

Code Analysis

Commit: 077dc4d

Enforce TaskRelation authorization checks during CalDAV relation handling

Mitigation Strategies

  • Upgrade the Vikunja backend deployment to version v2.6.0 or higher.
  • Restrict network access to the CalDAV endpoint (/dav/...) via web application firewall or reverse proxy if patching cannot be immediately performed.
  • Audit database task relations for unexpected cross-user or cross-project links established prior to patching.

Remediation Steps:

  1. Pull the latest Vikunja container image or binary release tagged v2.6.0 or later.
  2. Restart the Vikunja backend service to load the updated executable binaries.
  3. Inspect server logs for CalDAV request activity to ensure operational stability after patching.

References

Read the full report for GHSA-G38J-7V97-X298 on our website for more details including interactive diagrams and full exploit analysis.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.