Vikunja, Improper CORS Configuration, CVE-2026-25447 (Critical) -DC-Oct2026-3053

Listen to this Post

Vikunja ships with default CORS settings where `cors.origins` defaults to localhost wildcards and `Access-Control-Allow-Credentials` is set to true. When a production environment sets the mandatory service.publicurl, this value is appended to the default wildcard list instead of replacing it. Consequently, fully configured production deployments continue to trust every localhost origin. Because the token refresh endpoint accepts cookies automatically via cross-site requests and returns a fresh bearer JWT within the response body, any arbitrary web page running on a local port can perform a credentialed request and silently harvest a valid user access token, resulting in full account takeover.

DailyCVE Form:

Platform: Vikunja
Version: Prior to 2.3.0
Vulnerability : CORS Misconfiguration
Severity : Critical
date: 2026-03-30

Prediction: 2026-04-09

What Undercode Say

Bash Commands and Codes

docker build -f Dockerfile -t poc . && docker run --rm poc
import requests
def exploit_cors():
target = "https://vikunja.example.com/api/v1/user/token/refresh"
headers = {"Origin": "http://localhost:31337"}
response = requests.post(target, headers=headers, cookies={"vikunja_refresh_token": "dummy"}, verify=False)
print(response.json())

Exploit: (Educational Purposes!)

The exploitation relies on forcing a victim browser to interact with a malicious script hosted locally or via an untrusted port while logged into a production Vikunja instance. Because the server configuration appends the production public URL to default localhost wildcard entries while maintaining credential support (AllowCredentials: true), browsers permit cross-origin read access. The exploit script sends a `POST` request to the unauthenticated `/api/v1/user/token/refresh` endpoint with credentials included (credentials: 'include'). The browser appends the `HttpOnly` refresh token cookie automatically. The server processes the request, generates a new JWT token, and returns it inside the JSON response body, which the unauthorized local domain can read freely, granting full attacker control over the victim’s account.

Protection: from this CVE

Upgrade Vikunja to version 2.3.0 or later. Ensure that configuration handling properly substitutes or isolates `service.publicurl` instead of appending it to insecure localhost wildcards, and explicitly disable credential allowances on broad or wildcard CORS configurations.

Impact:

An attacker can completely compromise authenticated user accounts, steal sensitive task management data, modify private projects, and gain administrative control over self-hosted Vikunja instances without direct user interaction beyond visiting a malicious web page.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top