CVE-2026-35601 affects Vikunja, an open-source task management platform, in versions prior to 2.3.0. The vulnerability exists in the CalDAV output generator, which constructs iCalendar VTODO entries through unsafe string concatenation without proper RFC 5545 TEXT value escaping. Attackers can inject CRLF characters into task titles to break iCalendar property boundaries and inject arbitrary properties such as ATTACH, VALARM, or ORGANIZER. The vulnerability carries a CVSS 3.1 score of 4.1 (MEDIUM) with a network-based attack vector requiring low complexity and user authentication with required user interaction. The impact is limited to integrity compromise with no confidentiality or availability impact. The EPSS score of 0.00028 indicates this vulnerability ranks higher than approximately 0.08 percent of all CVEs in terms of exploitation probability. There is no evidence of active exploitation in the wild, and the vulnerability is not tracked on the CISA Known Exploited Vulnerabilities list. The inactive Hot List status and low EPSS score suggest minimal community attention and exploit availability. Organizations running Vikunja should prioritize upgrading to version 2.3.0 or later to remediate this issue, though immediate risk is considered low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.