{"id":"GHSA-9rg3-v78m-26q8","summary":"Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts)","details":"## Summary\n\nAPI token permission checks only match the HTTP method and route path. The `expand` query parameter on task read endpoints embeds data from other permission groups (task comments, reactions, time entry counts) without checking whether the token holds those scopes. A token scoped only to `tasks` read permissions can therefore read task comments and reactions it was explicitly not granted.\n\n## Details\n\n`models.CanDoAPIRoute` (`pkg/models/api_routes.go`, ~line 440) authorises API tokens purely by comparing `method` and `c.Path()` against the routes stored for each granted permission group. The query string is never consulted.\n\nThe task read endpoints accept `expand`:\n\n- `GET /api/v1/tasks/:task`, `GET /api/v1/tasks` (`pkg/models/tasks.go` ReadOne/ReadAll, `pkg/models/task_collection.go`)\n- `GET /api/v2/tasks/:id`, `GET /api/v2/tasks`, `GET /api/v2/projects/:project/tasks` (`pkg/routes/api/v2/tasks.go`, `task_collection.go`)\n\nAccepted values include `comments`, `comment_count`, `reactions`, `time_entries_count`. `addMoreInfoToTasks` (`pkg/models/tasks.go`, ~line 683) loads and embeds that data. At that layer only a `web.Auth` (the plain owner user, resolved by `auth.GetAuthFromClaims`) is available, so the token's scopes cannot be enforced there either.\n\nResult: the `tasks_comments`, `reactions`, and `time_entries` permission groups are advisory for any data reachable through a task expansion.\n\n## Impact\n\nA holder of an API token scoped to `tasks: [read_one]` or `tasks: [read_all]` (or `projects_views_tasks: [read_all]`) can read the full bodies of task comments, all reactions, and time entry counts on every task the token owner can access, despite `GET /api/v1|v2/tasks/:task/comments` and the reactions endpoints correctly returning 401 for the same token.\n\nThe leak is limited to data the token owner can already see, and is read-only. The realistic victim is a user who grants a narrowly scoped token to a third-party integration expecting comments to stay private.\n\n## Proof of Concept\n\nAgainst the test fixtures (`pkg/db/fixtures/api_tokens.yml`, token 1 has `{\"tasks\":[\"read_all\",\"update\"]}`, plaintext `tk_2eef46f40ebab3304919ab2e7e39993f75f29d2e`):\n\n```\nGET /api/v2/tasks/1/comments\nAuthorization: Bearer tk_2eef46f40ebab3304919ab2e7e39993f75f29d2e\n-\u003e 401 {\"code\":11,\"message\":\"missing, malformed, expired or otherwise invalid token provided\"}\n\nGET /api/v2/tasks?expand=comments&filter=id%3D1\nAuthorization: Bearer tk_2eef46f40ebab3304919ab2e7e39993f75f29d2e\n-\u003e 200, response items[0].comments contains the full comment objects\n```\n\nSame behaviour with `expand=reactions`, and on the v1 endpoints `GET /api/v1/tasks?expand=comments` / `GET /api/v1/tasks/1?expand=comments`. Any user-created token with only `tasks` read permissions reproduces this.\n\n## Recommended Fix\n\nEnforce expansions in the single existing choke point, `models.CanDoAPIRoute`: after the method/path match succeeds, read `c.QueryParams()[\"expand\"]` and require the token to hold the owning group's read permission for each value, e.g.\n\n- `comments`, `comment_count` -\u003e `tasks_comments.read_all`\n- `reactions` -\u003e `reactions.read_all`\n- `time_entries_count` -\u003e `time_entries.read_all`\n\n(`subtasks`, `buckets`, `is_unread` are task-level data and need nothing extra.) Doing this in the middleware covers both v1 and v2 without handler or model changes. Add a table-driven test alongside `pkg/webtests/api_token_method_matching_test.go` asserting a `tasks`-only token gets 401 with `expand=comments` and 200 once `tasks_comments.read_all` is added.","aliases":["CVE-2026-91983"],"modified":"2026-10-09T21:00:09.707298930Z","published":"2026-10-09T20:51:52Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-09T20:51:52Z","nvd_published_at":null,"cwe_ids":["CWE-863"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-9rg3-v78m-26q8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91983"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/pull/3688"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/commit/077dc4de79ce6f1ab59215a2c7bf9b30423685f2"},{"type":"PACKAGE","url":"https://github.com/go-vikunja/vikunja"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/releases/tag/v2.6.0"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vikunja-before-2.6.0-api-token-scope-bypass-via-expand-parameter"}],"affected":[{"package":{"name":"code.vikunja.io/api","ecosystem":"Go","purl":"pkg:golang/code.vikunja.io/api"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"},{"fixed":"2.6.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.5.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9rg3-v78m-26q8/GHSA-9rg3-v78m-26q8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}