Arbitrary Project Duplication Vulnerability in Vikunja Task Management Platform
CVE-2026-54766
5.3MEDIUM
What is CVE-2026-54766?
Vikunja is an open-source self-hosted task management platform that contains a vulnerability allowing an authenticated user to duplicate any project beneath a target parent project without proper permission checks. This flaw exists because the duplication process bypasses necessary write-permission verifications, resulting in possible unauthorized content injection into another user's project hierarchy. The issue has been addressed in version 2.4.0, highlighting the importance of updating to safeguard against such vulnerabilities.
Affected Version(s)
vikunja >= 0.21.0, < 2.4.0
