Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing passwords. Version 2.4.0 fixes the issue.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r6w9-259g-gwrv | Vikunja: Plaintext storage of password-reset/email-confirm tokens in database enables account takeover on DB read access |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing passwords. Version 2.4.0 fixes the issue. | |
| Title | Vikunja: Plaintext storage of password-reset/email-confirm tokens in database enables account takeover on DB read access | |
| Weaknesses | CWE-312 CWE-916 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T20:50:35.524Z
Reserved: 2026-07-13T22:04:59.678Z
Link: CVE-2026-62376
No data.
Status : Received
Published: 2026-10-09T21:17:05.627
Modified: 2026-10-09T21:17:05.627
Link: CVE-2026-62376
No data.
OpenCVE Enrichment
No data.
Github GHSA