CVE-2026-27819Disclosure(vikunja / vikunja)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restore.go of the go-vikunja/vikunja repository fails to sanitize file paths within the provided ZIP archive. A maliciously crafted ZIP can bypass the intended extraction directory to overwrite arbitrary files on the host system. Additionally, we’ve discovered that a malformed archive triggers a runtime panic, crashing the process immediately after the database has been wiped permanently. The application trusts the metadata in the ZIP archive. It uses the Name attribute of the zip.File struct directly in os.OpenFile calls without validation, allowing files to be written outside the intended directory. The restoration logic assumes a specific directory structure within the ZIP. When provided with a "minimalist" malicious ZIP, the application fails to validate the length of slices derived from the archive contents. Specifically, at line 154, the code attempts to access an index of len(ms)-2 on an insufficiently populated slice, triggering a panic. Version 2.0.0 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-248

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vikunja

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
vikunja

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-26: 3Technical Details · 2026-02-26: 302-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-27819 Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restore.go of the go-vi… https://www.cve.org/CVERecord?id=CVE-2026-27819

    Post summary

    The text references CVE-2026-27819 and identifies a vulnerable function in Vikunja before version 2.0.0, but it provides no evidence of exploitation, PoC, or patch availability.

    00000105
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27819: Vikunja's Kamikaze Restore: Zip Slips and Database Wipes A critical vulnerability in Vikunja's restore functionality allows for arbitrary file overwrites via Path Traversal (Zip Slip) and permanent data loss due to improper error handl... https://cvereports.com/reports/CVE-2026-27819

    Post summary

    The report discloses a critical path‑traversal flaw in Vikunja’s restore feature that can cause arbitrary file overwrites and permanent data loss.

    0000035
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27819 Path Traversal and Panic Vulnerability in Vikunja Task Management... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27819 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A path traversal and panic vulnerability (CVE-2026-27819) in Vikunja Task Management has been disclosed, with a link to details but no PoC, exploit code, or patch information.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvikunjavikunja---

Explore more