Arbitrary HTTP GET Requests Vulnerability in Vikunja Task Management Platform
CVE-2026-33675

6.4MEDIUM

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
24 March 2026

What is CVE-2026-33675?

The Vikunja task management platform contained a vulnerability in its migration helper functions, DownloadFile and DownloadFileWithHeaders, prior to version 2.2.1. These functions allow for arbitrary HTTP GET requests without sufficient Server-Side Request Forgery (SSRF) protections. When users trigger migrations from systems like Todoist or Trello, URLs for file attachments are passed directly to these functions, enabling potential attackers to manipulate Vikunja into retrieving internal network resources. This could result in unauthorized access to sensitive information. The issue was resolved in version 2.2.1, which now includes appropriate security measures to mitigate these risks.

Affected Version(s)

vikunja < 2.2.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.