CVE-2026-27819 | go-vikunja up to 1.x ZIP restore.go restoreConfig path traversal (GHSA-42wg-38gx-85rh)
A vulnerability, which was classified as critical, has been found in go-vikunja vikunja up to 1.x. This vulnerability affects the function restoreConfig of the file vikunja/pkg/modules/dump/restore.go of the component ZIP Handler. This manipulation causes path traversal.
This vulnerability is registered as CVE-2026-27819. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.