Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal
Published Mar 24, 2026
6.4
MEDIUMCVSS 4.0
EPSS 0.37%
Description
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper passes URLs from `window.open()` calls directly to `shell.openExternal()` without any validation or protocol allowlisting. An attacker who can place a link with `target="_blank"` (or that otherwise triggers `window.open`) in user-generated content can cause the victim's operating system to open arbitrary URI schemes, invoking local applications, opening local files, or triggering custom protocol handlers. Version 2.2.0 patches the issue.
Affected products
-
Affected
- ≥ 0.21.0, < 2.2.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| GO-Vikunja | Vikunja | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14909 Advisory
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-6q44-85gc-cjvf exploitx_refsource_CONFIRMVendor Advisory
- https://vikunja.io/changelog/vikunja-v2.2.0-was-released x_refsource_MISCRelease Notes
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14909 | Advisory | |
| https://github.com/go-vikunja/vikunja/security/advisories/GHSA-6q44-85gc-cjvf | exploitx_refsource_CONFIRMVendor Advisory | |
| https://vikunja.io/changelog/vikunja-v2.2.0-was-released | x_refsource_MISCRelease Notes |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data