Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. code.vikunja.io/api
  4. ›
  5. GHSA-fmmf-xq98-g327

GHSA-fmmf-xq98-g327: Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check

October 9, 2026

A project member with Write permission can delete an admin-tier link share on that project. The deletion authorization check reads the permission from an object populated only with URL IDs, rather than from the stored share. Its zero value is Read, so the check falls through to project Write permission instead of requiring Admin.

References

  • github.com/advisories/GHSA-fmmf-xq98-g327
  • github.com/go-vikunja/vikunja/security/advisories/GHSA-fmmf-xq98-g327

Code Behaviors & Features

Detect and mitigate GHSA-fmmf-xq98-g327 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.13.0 up to 2.6.0

Solution

Unfortunately, there is no solution available yet.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

go/code.vikunja.io/api/GHSA-fmmf-xq98-g327.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 11 Oct 2026 12:22:21 +0000.