CVE-2026-27616Disclosure(vikunja / vikunja)

LOWCVSS 7.3 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to upload SVG files as task attachments. SVG is an XML-based format that supports JavaScript execution through elements such as <script> tags or event handlers like onload. The application does not sanitize SVG content before storing it. When the uploaded SVG file is accessed via its direct URL, it is rendered inline in the browser under the application's origin. As a result, embedded JavaScript executes in the context of the authenticated user. Because the authentication token is stored in localStorage, it is accessible via JavaScript and can be retrieved by a malicious payload. Version 2.0.0 patches this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vikunja

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
vikunja

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-26: 3Technical Details · 2026-02-26: 302-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27616 Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to upload SVG files as task attachments. SVG is a… https://www.cve.org/CVERecord?id=CVE-2026-27616

    Post summary

    The CVE-2026-27616 entry notes that Vikunja versions before 2.0.0 allow SVG file uploads as task attachments, indicating a potential vulnerability. No PoC, exploit, patch, or active exploitation details are provided.

    00000109
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27616: Vikunja's Vector of Doom: Stored XSS via SVG A critical Stored Cross-Site Scripting (XSS) vulnerability in Vikunja allows attackers to hijack sessions via malicious SVG attachments. By exploiting loose MIME type handling and inline ren... https://cvereports.com/reports/CVE-2026-27616

    Post summary

    The report discloses a critical stored XSS vulnerability in Vikunja that enables session hijacking through malicious SVG attachments by exploiting loose MIME type handling.

    0000048
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27616 SVG File Upload XSS in Vikunja Task Management Platform Before 2.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27616 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new XSS vulnerability (CVE-2026-27616) affecting SVG file uploads in Vikunja Task Management Platform before version 2.0.0 has been reported, with links to vulnerability details and a notification.

    0000055
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvikunjavikunja---

Explore more