CVE-2026-33679 | go-vikunja up to 2.2.0 Image Parser pkg/utils/avatar.go DownloadImage server-side request forgery (GHSA-g9xj-752q-xh63)
A vulnerability identified as critical has been detected in go-vikunja vikunja up to 2.2.0. The affected element is the function DownloadImage of the file pkg/utils/avatar.go of the component Image Parser. Performing a manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-33679. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.