Executive brief
Vikunja is an open-source task management platform. A security issue was identified where shared project links remain active for up to 72 hours even after a user deletes the link or reduces its access permissions. This means an unauthorized person with a previously valid link could continue to view or modify project data long after their access was supposed to be revoked.
Technical details
Vikunja's link share authentication mechanism relies entirely on JWT claims without performing server-side database validation during the authorization process. Specifically, the 'GetLinkShareFromClaims' function in 'pkg/models/link_sharing.go' constructs the authorization object purely from the token's payload. Because these tokens have a default Time-To-Live (TTL) of 72 hours and lack a revocation mechanism (unlike user sessions), they remain valid for the remainder of their TTL even if the underlying share record is deleted from the database or its permission level is modified. An attacker with a previously issued token can maintain their original access level (Read, Write, or Admin) until the token expires. The fix involves adding database lookups to verify the existence and current permission level of the share during token validation.
Affected products
- Vikunja Vikunja <= 2.2.2
Timeline
- 2026-04-09: disclosed: Vulnerability reported to vendor
- 2026-04-10: advisory: GitHub Advisory published
- 2026-04-10: patched: Fixed in version 2.3.0