Product
Vikunja versions up to 2.4.0 are vulnerable to authorization bypass via principal-type confusion, allowing attackers with a valid link-share JWT to manipulate team rosters and bot users.