PT-2026-24782 · Taskosaur+1 · Taskosaur

G3Xar

·

Published

2026-03-11

·

Updated

2026-03-12

·

CVE-2026-31874

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Taskosaur version 1.0.0
Description Taskosaur is an open source project management platform with conversational AI for task execution within the application. The application does not properly validate or restrict the role parameter during the user registration process. An attacker can manually modify the request payload to assign themselves elevated privileges. The backend does not enforce role assignment restrictions or ignore client-supplied role parameters, allowing the server to accept the manipulated value and create an account with SUPER ADMIN privileges. This enables any unauthenticated attacker to register a fully privileged administrative account. The vulnerable parameter is role.
Recommendations Versions prior to 1.0.0 are not affected. For version 1.0.0, properly validate and restrict the role parameter during the user registration process to prevent unauthorized privilege escalation.

Exploit

Fix

IDOR

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31874
GHSA-R6GJ-4663-P5MR

Affected Products

Taskosaur