
🟠 CVE-2026-33678 - High Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`WHERE id = ?`), ignoring the task ID from t... https://www.thehackerwire.com/vulnerability/CVE-2026-33678/ https://t.co/YO39zftpAC
Post summary
The tweet announces CVE‑2026‑33678 in Vikunja, describing an access‑control flaw where attachment queries ignore task IDs, but it provides neither proof of exploitation nor remediation guidance.


