GHSA-hjx8-qv73-f7cm: Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed
A collaborator removed from a project keeps a live, automatic feed of that project’s contents, because nothing on any revocation path deletes the webhook they created while they had access.
Vikunja already has a revocation-cleanup routine that deletes other derived rows for exactly this reason. Its set is {task_assignees, subscriptions}. webhooks and link_shares — the only two rows that carry a live channel into the project — are not in it, and the routine is wired to one of four revocation paths.
References
Code Behaviors & Features
Detect and mitigate GHSA-hjx8-qv73-f7cm with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →