CVE-2026-31874Disclosure(taskosaur / taskosaur)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate or restrict the role parameter during the user registration process. An attacker can manually modify the request payload and assign themselves elevated privileges. Because the backend does not enforce role assignment restrictions or ignore client-supplied role parameters, the server accepts the manipulated value and creates the account with SUPER_ADMIN privileges. This allows any unauthenticated attacker to register a fully privileged administrative account.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • taskosaur

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • False Positive: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-11); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
taskosaur

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-12: 1Technical Details · 2026-03-11: 203-1103-12
Signal classification3 categories
Disclosure
250.0%
False Positive
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure2False Positive1
2026-03-121
General1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-31874 Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate or rest… https://www.cve.org/CVERecord?id=CVE-2026-31874

    Post summary

    The CVE is cited for Taskosaur 1.0.0 with an incomplete mention of a validation issue, but no exploitation details, patches, or active misuse are reported.

    00000180
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-31874: CRITICAL] Taskosaur has a security vulnerability in version 1.0.0 allowing attackers to gain SUPER_ADMIN privileges during registration due to improper validation of role parameters.#cve,CVE-2026-31874,#cybersecurity https://cvefind.com/CVE-2026-31874

    Post summary

    The post discloses a critical privilege‑escalation flaw in Taskosaur v1.0.0, enabling attackers to obtain SUPER_ADMIN rights via registration, but offers no PoC, exploit, or remediation details.

    0000055
    602 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-31874 - Critical Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate or restrict the role paramet... https://www.thehackerwire.com/vulnerability/CVE-2026-31874/ https://t.co/SqjEDiibuR

    Post summary

    The tweet announces CVE‑2026‑31874 as a critical flaw in Taskosaur 1.0.0 that fails to properly validate or restrict the role parameter, with a reference to an external article for further detail.

    0000044
    134 followersView on X
  • 0day Signal@0dayPublishing
    False Positive

    🚨 CVE-2026-31874: Taskosaur Improper Role Assignme... Trusting client-side role parameters in registration? That's not a bug, that's a feature request for every script kiddi... https://zerodaysignal.com/vulnerability/CVE-2026-31874 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post challenges the existence of CVE-2026-31874, labeling it a false positive with no supporting technical details, PoC, exploitation evidence, or patch information.

    0000053
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptaskosaurtaskosaur1.0.0node.js-

Explore more