CVE-2026-35601 - Vikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output

CVE ID :CVE-2026-35601
Published : April 10, 2026, 4:08 p.m. | 57 minutes ago
Description :Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT value escaping. User-controlled task titles containing CRLF characters break the iCalendar property boundary, allowing injection of arbitrary iCalendar properties such as ATTACH, VALARM, or ORGANIZER. This vulnerability is fixed in 2.3.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

from Latest Vulnerabilities https://ift.tt/Jtgc2e6

Post a Comment

Previous Post Next Post