
CVE-2026-33679 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client… https://www.cve.org/CVERecord?id=CVE-2026-33679
Post summary
Vikunja’s earlier releases contain a flaw in the DownloadImage function, resolved in v2.2.1; no PoC or exploitation evidence is presented.

