GHSA-4hv6-xc92-j86g: Vikunja: WebSocket authentication ignores server-side session state, so revoked sessions keep receiving live pushes
Vikunja v2.6.0 introduced server-side sessions with revocation semantics: DELETE /api/v2/user/sessions/{id} documents “Revokes a specific session by its UUID”, and enabling TOTP calls DeleteAllUserSessions to invalidate all sessions. The WebSocket endpoint accepts any cryptographically valid user JWT without ever resolving its sid (session id) claim against the sessions table. A connection authenticated before revocation stays authenticated and continues to receive live pushes indefinitely, and even brand-new WebSocket connections are accepted with a token whose session was deleted. The revocation feature therefore does not cover the WebSocket boundary at all.
References
Code Behaviors & Features
Detect and mitigate GHSA-4hv6-xc92-j86g with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →