CVE 5.4 MEDIUM

Vikunja has HTML Injection via Task Titles in Overdue Email Notifications_CVE-2026-35600

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into Markdown link syntax in overdue email notifications without escaping Markdown special characters. When rendered by goldmark and sanitized by bluemonday (which allows <a> and <img> tags), injected Markdown constructs produce phishing links and tracking pixels in legitimate notification emails. This vulnerability is fixed in 2.3.0.

Basic Information

ID CVE-2026-35600
Source GitHub_M
Published Apr 10, 2026 at 16:07

Affected Product

Vendor go-vikunja
Product vikunja
Version < 2.3.0
Affected Versions go-vikunja vikunja < 2.3.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.