
CVE-2026-35602 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from the JSON… https://www.cve.org/CVERecord?id=CVE-2026-35602
Post summary
CVE-2026-35602 impacts Vikunja's file import endpoint via an attacker‑controlled Size field; no proof‑of‑concept, exploit tool, patch, or active exploitation information is provided.
