← Back

CVE-2026-33473

nvd nist
Published: Mar 24, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.1 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any user that has enabled 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.2.1 patches the issue.

Affected (1)

Products: Vikunja: Vikunja
1 product
Vikunja
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 0.13 to 2.2.1

References (3)

Source: security-advisories@github.com
ExploitVendor Advisory
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Release Notes

Timeline

No history available yet.