CVE Explorer
CVE-2026-33334
Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `contextIsolation` or `sandbox`. This means any cross-site scripting (XSS) vulnerability in the Vikunja web frontend -- present or future -- automatically escalates to full remote code execution on the victim's machine, as injected scripts gain access to Node.js APIs. Version 2.2.0 fix
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-94","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4ac0296674697d2df6dbed4f15f2305a1c09e3b8e31f3c49a40557b85ebfdd9d · sha256:cd6925e0b650218e… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4ac0296674697d2df6dbed4f15f2305a1c09e3b8e31f3c49a40557b85ebfdd9d · sha256:cd6925e0b650218e… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"vikunja","vendor":"go-vikunja","versions":[{"status":"affected","version":">= 0.21.0, < 2.2.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4ac0296674697d2df6dbed4f15f2305a1c09e3b8e31f3c49a40557b85ebfdd9d · sha256:cd6925e0b650218e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.5,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4ac0296674697d2df6dbed4f15f2305a1c09e3b8e31f3c49a40557b85ebfdd9d · sha256:cd6925e0b650218e… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-94","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4ac0296674697d2df6dbed4f15f2305a1c09e3b8e31f3c49a40557b85ebfdd9d · sha256:cd6925e0b650218e… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4ac0296674697d2df6dbed4f15f2305a1c09e3b8e31f3c49a40557b85ebfdd9d · sha256:cd6925e0b650218e… · /containers/cna/problemTypes/1/descriptions/0
Source references
2 source assertions{"name":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xh67-63q3-hf7g","tags":["x_refsource_CONFIRM"],"url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xh67-63q3-hf7g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4ac0296674697d2df6dbed4f15f2305a1c09e3b8e31f3c49a40557b85ebfdd9d · sha256:cd6925e0b650218e… · /containers/cna/references/0
{"name":"https://vikunja.io/changelog/vikunja-v2.2.0-was-released","tags":["x_refsource_MISC"],"url":"https://vikunja.io/changelog/vikunja-v2.2.0-was-released"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4ac0296674697d2df6dbed4f15f2305a1c09e3b8e31f3c49a40557b85ebfdd9d · sha256:cd6925e0b650218e… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.