CVE-2026-33677 | go-vikunja up to 2.2.0 /api/v1/projects/ basic_auth_user/basic_auth_password information disclosure (GHSA-7c2g-p23p-4jg3)
A vulnerability was found in go-vikunja vikunja up to 2.2.0. It has been rated as problematic. This issue affects some unknown processing of the file /api/v1/projects/. This manipulation of the argument basic_auth_user/basic_auth_password causes information disclosure.
This vulnerability is tracked as CVE-2026-33677. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.