THREAT OPS › Threat News › [GHSA] GHSA-44v6-7fxq-vgf4 (medium) — Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
[GHSA] GHSA-44v6-7fxq-vgf4 (medium) — Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
GHSA-44v6-7fxq-vgf4 Severity: medium CVE: CVE-2026-55064
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
## Summary
The fix for CVE-2026-35595 (project re-parenting privilege escalation) only gates reparent operations when `parent_project_id > 0`. A user with Write (but not Admin) permission on a shared ch
Indicators of compromise
- CVE-2026-35595cve
- CVE-2026-55064cve
Original source: https://github.com/advisories/GHSA-44v6-7fxq-vgf4