PT-2026-27446 · Vikunja · Vikunja

Restriction

·

Publicado

2026-03-24

·

Atualizado

2026-03-27

·

CVE-2026-33675

CVSS v3.1

6.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.2.1
Description Vikunja is a self-hosted task management platform. Prior to version 2.2.1, the DownloadFile and DownloadFileWithHeaders functions within the pkg/modules/migration/helpers.go file do not have Server-Side Request Forgery (SSRF) protection. During Todoist or Trello migrations, file attachment URLs from the third-party API responses are directly used by these functions. This allows an attacker to make the Vikunja server request internal network resources and return the response as a downloadable task attachment. The vulnerable functions are DownloadFile and DownloadFileWithHeaders.
Recommendations Update to version 2.2.1 or later.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33675
GHSA-G66V-54V9-52PR
GO-2026-4851
SUSE-SU-2026:1135-1

Produtos afetados

Vikunja