
CVE-2026-33677 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAut… https://www.cve.org/CVERecord?id=CVE-2026-33677
Post summary
CVE-2026-33677 in Vikunja exposes BasicAuth credentials through the GET /api/v1/projects/:project/webhooks endpoint prior to version 2.2.1.

