<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:57:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277226</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277226</link>
      <description>EUVD-2026-277226</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277226</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33677</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33677</link>
      <description>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAuth credentials (`basic_auth_user` and `basic_auth_password`) in plaintext to any user with read access to the project. While the existing code correctly masks the HMAC `secret` field, the BasicAuth fields added in a later migration were not given the same treatment. This allows read-only collaborators to steal credentials intended for authenticating against external webhook receivers. Version 2.2.1 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAuth credentials (`basic_auth_user` and `basic_auth_password`) in plaintext to any user with read access to the project. While the existing code correctly masks the HMAC `secret` field, the BasicAuth fields added in a later migration were not given the same treatment. This allows read-only collaborators to steal credentials intended for authenticating against external webhook receivers. Version 2.2.1 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33677</guid>
    </item>
    <item>
      <title>GHSA-7c2g-p23p-4jg3 — Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7c2g-p23p-4jg3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAuth credentials (`basic_auth_user` and `basic_auth_password`) in plaintext to any user with read access to the project. While the existing code correctly masks the HMAC `secret` field, the BasicAuth fields added in a later migration were not given the same treatment. This allows read-only collaborators to steal credentials intended for authenticating against external webhook receivers.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;When listing project webhooks, the `ReadAll` method in `pkg/models/webhooks.go` (line 203) only requires project read access:&lt;/p&gt;
&lt;p&gt;```go
// pkg/models/webhooks.go:203-244
func (w *Webhook) ReadAll(s *xorm.Session, a web.Auth, _ string, page int, perPage int) (result interface{}, resultCount int, numberOfTotalItems int64, err error) {
	p := &amp;amp;Project{ID: w.ProjectID}
	can, _, err := p.CanRead(s, a)  // Only requires read permission
	if err != nil {
		return nil, 0, 0, err
	}
	if !can {
		return nil, 0, 0, ErrGenericForbidden{}
	}&lt;/p&gt;
&lt;p&gt;// ... fetches webhooks from DB ...&lt;/p&gt;
&lt;p&gt;for _, webhook := range ws {
		webhook.Secret = &amp;#34;&amp;#34;  // HMAC secret is masked
		// BasicAuthUser and BasicAuthPassword are NOT masked
		if createdBy, has := users[webhook.CreatedByID]; has {
			webhook.CreatedBy = createdBy
		}
	}&lt;/p&gt;
&lt;p&gt;return ws, len(ws), total, err
}
```&lt;/p&gt;
&lt;p&gt;The `Webhook` struct defines both fields with JSON serialization tags, so they are included in API responses:&lt;/p&gt;
&lt;p&gt;```go
// pkg/models/webhooks.go:63-64
BasicAuthUser     st…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `GET /api/v1/projects/:project/webhooks` endpoint returns webhook BasicAuth credentials (`basic_auth_user` and `basic_auth_password`) in plaintext to any user with read access to the project. While the existing code correctly masks the HMAC `secret` field, the BasicAuth fields added in a later migration were not given the same treatment. This allows read-only collaborators to steal credentials intended for authenticating against external webhook receivers.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;When listing project webhooks, the `ReadAll` method in `pkg/models/webhooks.go` (line 203) only requires project read access:&lt;/p&gt;
&lt;p&gt;```go
// pkg/models/webhooks.go:203-244
func (w *Webhook) ReadAll(s *xorm.Session, a web.Auth, _ string, page int, perPage int) (result interface{}, resultCount int, numberOfTotalItems int64, err error) {
	p := &amp;amp;Project{ID: w.ProjectID}
	can, _, err := p.CanRead(s, a)  // Only requires read permission
	if err != nil {
		return nil, 0, 0, err
	}
	if !can {
		return nil, 0, 0, ErrGenericForbidden{}
	}&lt;/p&gt;
&lt;p&gt;// ... fetches webhooks from DB ...&lt;/p&gt;
&lt;p&gt;for _, webhook := range ws {
		webhook.Secret = &amp;#34;&amp;#34;  // HMAC secret is masked
		// BasicAuthUser and BasicAuthPassword are NOT masked
		if createdBy, has := users[webhook.CreatedByID]; has {
			webhook.CreatedBy = createdBy
		}
	}&lt;/p&gt;
&lt;p&gt;return ws, len(ws), total, err
}
```&lt;/p&gt;
&lt;p&gt;The `Webhook` struct defines both fields with JSON serialization tags, so they are included in API responses:&lt;/p&gt;
&lt;p&gt;```go
// pkg/models/webhooks.go:63-64
BasicAuthUser     st…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7c2g-p23p-4jg3</guid>
    </item>
  </channel>
</rss>
