Markdown Injection Vulnerability in Vikunja Task Management Platform
CVE-2026-35600

5.4MEDIUM

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
10 April 2026

What is CVE-2026-35600?

The Vikunja task management platform contains a vulnerability where task titles are improperly embedded into Markdown link syntax in overdue email notifications. This flaw allows for the injection of malicious Markdown constructs, potentially leading to the display of phishing links and tracking pixels in legitimate user emails. As a result, users could be misled into clicking on harmful links. This issue was addressed in version 2.3.0, which sanitizes inputs to prevent such exploitation.

Affected Version(s)

vikunja < 2.3.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.