THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f27p-pw2p-9pr4 (medium) — Vikunja has a project duplication bypasses write-permission check on the target parent project

[GHSA] GHSA-f27p-pw2p-9pr4 (medium) — Vikunja has a project duplication bypasses write-permission check on the target parent project

medgithub_advisoriesPublished 2026-08-28

GHSA-f27p-pw2p-9pr4 Severity: medium CVE: CVE-2026-54766

Vikunja has a project duplication bypasses write-permission check on the target parent project

## Summary

The project-duplication endpoint fails to enforce write access to the target parent project. Any authenticated (non-link-share) user can duplicate a project they can read into **any** parent project on the instance, regardless of whet

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f27p-pw2p-9pr4