Junglewise Threat Intelligence

CVE-2026-35600: Vikunja Markdown injection in email notifications

CVE-2026-35600 · Severity: medium · CVSS 5.4 · Published 2026-04-10

Technologies: code.vikunja.io/api (Go), Vikunja. Vendors: Go, Vikunja.

Executive brief

Vikunja is an open-source to-do list application. A vulnerability in how it handles task titles allows an attacker to inject malicious links or tracking pixels into automated email notifications sent to other users. This could be used for phishing attacks or to track when a user opens their email, potentially compromising user privacy or leading to account takeover if a user clicks a deceptive link.

Technical details

The vulnerability exists in the notification generation logic (specifically `pkg/models/notifications.go`), where task titles are concatenated directly into Markdown link syntax `[TITLE](URL)`. An attacker with project write access can craft a task title containing Markdown control characters (like `]` and `[`) to break out of the intended link and inject arbitrary Markdown. When the backend renders this Markdown to HTML using the `goldmark` library and sanitizes it with `bluemonday`, the resulting HTML retains injected `<a>` and `<img>` tags. This allows for the insertion of phishing links and tracking pixels into legitimate system-generated emails. The issue is fixed in version 2.3.0.

Affected products

  • go-vikunja Vikunja <= 2.2.2

Timeline

  • 2026-04-09: disclosed
  • 2026-04-10: advisory
  • 2026-04-10: patched

References

Related threats