<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T23:33:22.811064+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277226</id>
    <title>EUVD-2026-277226</title>
    <updated>2026-10-05T23:33:22.870292+00:00</updated>
    <content>EUVD-2026-277226</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277226"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33677</id>
    <title>fkie_cve-2026-33677</title>
    <updated>2026-10-05T23:33:22.870350+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAuth credentials (`basic_auth_user` and `basic_auth_password`) in plaintext to any user with read access to the project. While the existing code correctly masks the HMAC `secret` field, the BasicAuth fields added in a later migration were not given the same treatment. This allows read-only collaborators to steal credentials intended for authenticating against external webhook receivers. Version 2.2.1 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7c2g-p23p-4jg3</id>
    <title>GHSA-7c2g-p23p-4jg3 — Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API</title>
    <updated>2026-10-05T23:33:22.870415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.vikunja.io/api</p>
<p>## Summary</p>
<p>The `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAuth credentials (`basic_auth_user` and `basic_auth_password`) in plaintext to any user with read access to the project. While the existing code correctly masks the HMAC `secret` field, the BasicAuth fields added in a later migration were not given the same treatment. This allows read-only collaborators to steal credentials intended for authenticating against external webhook receivers.</p>
<p>## Details</p>
<p>When listing project webhooks, the `ReadAll` method in `pkg/models/webhooks.go` (line 203) only requires project read access:</p>
<p>```go
// pkg/models/webhooks.go:203-244
func (w *Webhook) ReadAll(s *xorm.Session, a web.Auth, _ string, page int, perPage int) (result interface{}, resultCount int, numberOfTotalItems int64, err error) {
	p := &amp;Project{ID: w.ProjectID}
	can, _, err := p.CanRead(s, a)  // Only requires read permission
	if err != nil {
		return nil, 0, 0, err
	}
	if !can {
		return nil, 0, 0, ErrGenericForbidden{}
	}</p>
<p>// ... fetches webhooks from DB ...</p>
<p>for _, webhook := range ws {
		webhook.Secret = ""  // HMAC secret is masked
		// BasicAuthUser and BasicAuthPassword are NOT masked
		if createdBy, has := users[webhook.CreatedByID]; has {
			webhook.CreatedBy = createdBy
		}
	}</p>
<p>return ws, len(ws), total, err
}
```</p>
<p>The `Webhook` struct defines both fields with JSON serialization tags, so they are included in API responses:</p>
<p>```go
// pkg/models/webhooks.go:63-64
BasicAuthUser     st…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7c2g-p23p-4jg3"/>
  </entry>
</feed>
