Mmastodon TechnologyCybersecurity first seen 5 h ago, last 5 h ago, peak #11
High-severity vulnerability found in Vikunja task manager
Original: 🟠 CVE-2026-57458 - High (8.1) Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped
A vulnerability tracked as CVE-2026-57458 with a severity score of 8.1 affects Vikunja 2.3.0, an open-source self-hosted task management platform. A scoped API token restricted to the oauth.authorize permission can call the OAuth authorize endpoint, obtain an authorization code and exchange it, escalating beyond its intended scope. Security trackers are flagging it, and self-hosted administrators are advised to review their exposure and apply fixes.
Why now: Administrators of self-hosted Vikunja instances are checking whether they need to patch a high-severity token escalation flaw.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1656419