
CVE-2026-33313 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read any task comment by ID, regardless of whether t… https://www.cve.org/CVERecord?id=CVE-2026-33313
Post summary
The text announces that before version 2.2.0, authenticated users in Vikunja can read any task comment by ID, detailing the vulnerability but providing no PoC, exploit, patch, or exploitation evidence.

