HIGH 7.3 Go
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure
GHSA-7jp5-298q-jg98 · CVE-2026-27616 · GO-2026-4553
Published · Modified
Description
Details
The application allows users to upload SVG files as task attachments. SVG is an XML-based format that supports JavaScript execution through elements such as