top of page
perceptive_background_267k.jpg

Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate o…

Published:

10 March 2026 at 23:00:00

Alert date:

11 March 2026 at 20:06:05

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

Taskosaur version 1.0.0, an open source project management platform with conversational AI, contains a critical privilege escalation vulnerability. The application fails to properly validate the role parameter during user registration, allowing attackers to modify request payloads and assign themselves elevated privileges. The backend does not enforce role assignment restrictions or ignore client-supplied role parameters, enabling unauthenticated attackers to register accounts with SUPER_ADMIN privileges. This vulnerability allows complete administrative access to the platform without authentication.

Technical details

Mitigation steps:

Affected products:

Taskosaur

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page