Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35601

17
FAUCET Score

CVE-2026-35601 affects Vikunja, an open-source task management platform, in versions prior to 2.3.0. The vulnerability exists in the CalDAV output generator, which constructs iCalendar VTODO entries through unsafe string concatenation without proper RFC 5545 TEXT value escaping. Attackers can inject CRLF characters into task titles to break iCalendar property boundaries and inject arbitrary properties such as ATTACH, VALARM, or ORGANIZER. The vulnerability carries a CVSS 3.1 score of 4.1 (MEDIUM) with a network-based attack vector requiring low complexity and user authentication with required user interaction. The impact is limited to integrity compromise with no confidentiality or availability impact. The EPSS score of 0.00028 indicates this vulnerability ranks higher than approximately 0.08 percent of all CVEs in terms of exploitation probability. There is no evidence of active exploitation in the wild, and the vulnerability is not tracked on the CISA Known Exploited Vulnerabilities list. The inactive Hot List status and low EPSS score suggest minimal community attention and exploit availability. Organizations running Vikunja should prioritize upgrading to version 2.3.0 or later to remediate this issue, though immediate risk is considered low.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.0CPE matchmatch criteria
cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
9.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 9th percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: code.vikunja.io/apiFixed in: 2.3.0

Vendor Advisories (1)

goGHSA-2g7h-7rqr-9p4rmedium

Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output

Apr 10, 2026

References

github.com / go-vikunja/vikunja/pull/2580
Issue Tracking
github.com / go-vikunja/vikunja/releases/tag/v2.3.0
Release Notes
github.com / go-vikunja/vikunja/security/advisories/GHSA-2g7h-7rqr-9p4r
ExploitVendor Advisory