


Perceptive Security
SOC/SIEM Consultancy

Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate o…
Published:
10 March 2026 at 23:00:00
Alert date:
11 March 2026 at 20:06:05
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Taskosaur version 1.0.0, an open source project management platform with conversational AI, contains a critical privilege escalation vulnerability. The application fails to properly validate the role parameter during user registration, allowing attackers to modify request payloads and assign themselves elevated privileges. The backend does not enforce role assignment restrictions or ignore client-supplied role parameters, enabling unauthenticated attackers to register accounts with SUPER_ADMIN privileges. This vulnerability allows complete administrative access to the platform without authentication.
Technical details
Mitigation steps:
Affected products:
Taskosaur
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-31874
https://github.com/Taskosaur/Taskosaur/commit/159a5a8f43761561100a57d34309830550028932
https://github.com/Taskosaur/Taskosaur/security/advisories/GHSA-r6gj-4663-p5mr
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
