Launch Week Day 1: Announcing Security Design Review
HIGH 7.3 Go

Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure

GHSA-7jp5-298q-jg98 · CVE-2026-27616 · GO-2026-4553

Published · Modified

Description

Details
The application allows users to upload SVG files as task attachments. SVG is an XML-based format that supports JavaScript execution through elements such as