PT-2026-27446 · Vikunja · Vikunja

Restriction

·

Published

2026-03-24

·

Updated

2026-03-27

·

CVE-2026-33675

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.2.1
Description Vikunja is a self-hosted task management platform. Prior to version 2.2.1, the DownloadFile and DownloadFileWithHeaders functions within the pkg/modules/migration/helpers.go file do not have Server-Side Request Forgery (SSRF) protection. During Todoist or Trello migrations, file attachment URLs from the third-party API responses are directly used by these functions. This allows an attacker to make the Vikunja server request internal network resources and return the response as a downloadable task attachment. The vulnerable functions are DownloadFile and DownloadFileWithHeaders.
Recommendations Update to version 2.2.1 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-33675
GHSA-G66V-54V9-52PR
GO-2026-4851
SUSE-SU-2026:1135-1

Affected Products

Vikunja