PT-2026-27442 · Vikunja+2 · Vikunja+2

Highkolaente

·

Published

2026-03-24

·

Updated

2026-03-24

·

CVE-2026-33334

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vikunja versions 0.21.0 through 2.1.9
Description Vikunja is a self-hosted task management platform. Versions 0.21.0 through 2.1.9 of the Vikunja Desktop Electron wrapper enable nodeIntegration in the renderer process without contextIsolation or sandbox. This configuration allows any cross-site scripting (XSS) vulnerability in the Vikunja web frontend to potentially lead to full remote code execution on a victim’s machine, as injected scripts gain access to Node.js APIs.
Recommendations Update to version 2.2.0 or later.

Exploit

Fix

Improper Privilege Management

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-33334
GHSA-XH67-63Q3-HF7G

Affected Products

Electron
Vikunja
Vikunja Desktop