Arbitrary HTTP GET Requests Vulnerability in Vikunja Task Management Platform
CVE-2026-33675
6.4MEDIUM
What is CVE-2026-33675?
The Vikunja task management platform contained a vulnerability in its migration helper functions, DownloadFile and DownloadFileWithHeaders, prior to version 2.2.1. These functions allow for arbitrary HTTP GET requests without sufficient Server-Side Request Forgery (SSRF) protections. When users trigger migrations from systems like Todoist or Trello, URLs for file attachments are passed directly to these functions, enabling potential attackers to manipulate Vikunja into retrieving internal network resources. This could result in unauthorized access to sensitive information. The issue was resolved in version 2.2.1, which now includes appropriate security measures to mitigate these risks.
Affected Version(s)
vikunja < 2.2.1
