Markdown Injection Vulnerability in Vikunja Task Management Platform
CVE-2026-35600
5.4MEDIUM
What is CVE-2026-35600?
The Vikunja task management platform contains a vulnerability where task titles are improperly embedded into Markdown link syntax in overdue email notifications. This flaw allows for the injection of malicious Markdown constructs, potentially leading to the display of phishing links and tracking pixels in legitimate user emails. As a result, users could be misled into clicking on harmful links. This issue was addressed in version 2.3.0, which sanitizes inputs to prevent such exploitation.
Affected Version(s)
vikunja < 2.3.0
