Executive brief
Taiga, a project management platform, contains a security flaw that allows unauthorized individuals to view sensitive information about private projects. By sending specific requests to the system, an attacker can see a list of project members, their full names, and internal workflow settings without needing a password. This could lead to the exposure of team structures and user identities for projects intended to be confidential.
Technical details
A missing authorization vulnerability exists in the 'filters_data' action within the UserStory, Task, Issue, and Epic API viewsets of taiga-back. The 'filters_data_perms' is set to 'AllowAny', and the underlying service-layer helpers (such as _get_userstories_assigned_to) execute raw SQL queries against project membership and metadata tables using an unchecked project ID. Because project IDs are sequential integers, an unauthenticated attacker can enumerate private projects to extract user IDs, full names, gravatar hashes, and workflow configurations (statuses, roles, priorities). This bypasses standard access controls that correctly protect other project-related API endpoints.
Affected products
- Taiga taiga-back <= 6.10.1
Timeline
- 2026-05-22: disclosed: Reported to vendor via email
- 2026-07-02: disclosed: Public GitHub issue opened
- 2026-07-21: advisory: NVD and VulnCheck advisory published