Listen to this Post
The vulnerability resides in the CalDAV storage provider route handler of Vikunja, specifically within the task relation persistence logic. When creating task relations through the standard REST API, the application correctly enforces permission checks via the `TaskRelation.CanCreate` method, ensuring that callers cannot link tasks across unauthorized project boundaries. However, the CalDAV protocol endpoint path completely bypasses this crucial authorization mechanism. During the iCalendar import and parsing process, the application processes related tasks using an unscoped unique identifier lookup (models.GetTaskSimpleByUUID) and directly invokes creation methods without validating whether the authenticated user possesses proper access rights to the target victim task or its containing project. Because task UIDs are exposed to anyone who has ever held read access to a project—and because revoking project membership does not purge learned unique identifiers from a former collaborator’s memory—a removed collaborator can exploit this oversight. By crafting a malicious CalDAV iCalendar payload containing a `RELATED-TO;RELTYPE=CHILD` property pointing to an arbitrary victim task UID, an attacker can force a persisted write operation into the database. This unauthorized write action successfully creates a cross-project task relation edge, effectively bypassing security controls and feeding into secondary information disclosure flaws.
DailyCVE Form:
Platform: Vikunja API
Version: v2.5.0 and prior
Vulnerability : Missing Authorization
Severity : Moderate
date: March 23, 2026
Prediction: Patched in v2.5.1
What Undercode Say
Bash Commands and Code Implementation
Baseline control check via REST API (refused with 403 Forbidden)
curl -X PUT "http://localhost:3456/api/v1/tasks/attackerTask/relations" \
-H "Authorization: Bearer <attacker_jwt>" \
-H "Content-Type: application/json" \
-d '{"task_id":"attackerTask","other_task_id":"victimTask","relation_kind":"subtask"}'
Exploit execution via CalDAV protocol (succeeds with 201 Created)
curl -X PUT "http://localhost:3456/dav/projects/attackerProject/attackerTaskUID.ics" \
-u "attacker:password" \
-H "Content-Type: text/calendar" \
--data-binary @- <<EOF
BEGIN:VCALENDAR
VERSION:2.0
BEGIN:VTODO
UID:attackerTaskUID
RELATED-TO;RELTYPE=CHILD:victimTaskUID
END:VTODO
END:VCALENDAR
EOF
Exploit: (Educational Purposes!)
The exploitation relies on abusing the CalDAV interface rather than the standard REST API endpoint. An attacker who is a former project collaborator retains knowledge of task Universally Unique Identifiers (UIDs) from their previous read access, even after their project privileges have been formally revoked. By targeting the CalDAV DAV storage endpoint, the attacker issues a `PUT` request containing a crafted `.ics` file. Inside this file, the iCalendar property `RELATED-TO;RELTYPE=CHILD` specifies the target victimTaskUID. Because the underlying function `persistRelations` in `pkg/routes/caldav/listStorageProvider.go` performs an unscoped lookup using `models.GetTaskSimpleByUUID` and directly executes `rel.Create(s, a)` without triggering TaskRelation.CanCreate, the server accepts the input and writes a new row into the `task_relations` table. This results in a persistent, attacker-attributable relationship linked to a victim task in a project the attacker cannot access.
Protection: from this CVE
To remediate this vulnerability, developers must ensure that all code paths—including alternative protocol handlers like CalDAV—enforce identical authorization constraints as the core REST API. Specifically, the CalDAV relation creation routine must be routed through `TaskRelation.CanCreate` to validate user permissions before database insertion. Furthermore, database queries resolving task UIDs via `models.GetTaskSimpleByUUID` must be strictly scoped to verify that the calling user maintains active access to the target project. Administrators running vulnerable instances should immediately upgrade to the patched release version provided by the vendor.
Impact:
The primary impact of this vulnerability is broken access control resulting from missing authorization checks during task relation creation. Although direct reading of the related task’s full contents may require separate disclosure pathways, this unauthorized write primitive allows malicious actors to pollute the relation sets of arbitrary tasks across the entire application instance. Furthermore, successfully establishing these cross-project subtask edges removes the preconditions required for secondary information disclosure vulnerabilities, enabling unauthorized correlation and tracking of sensitive tasks across isolated project boundaries.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

