Skip to main content
Loading…
    CVE-2026-33679 — Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when d — CVE Database · The Intelligence Room