CVE Feed

    Dashboard / CVE / CVE-2026-31874

    CVE-2026-31874

    Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate or restrict the role parameter during the user registration process. An attacker can manually modify the request payload and assign themselves elevated privileges. Because the backend does not enforce role assignment restrictions or ignore client-supplied role parameters, the server accepts the manipulated value and creates the account with SUPER_ADMIN privileges. This allows any unauthenticated attacker to register a fully privileged administrative account.

    Published:Mar 11, 2026
    Last Modified:Mar 23, 2026
    EPS:Mar 11, 2026
    EPSS Score:0.00157
    CVSS Score:9.8

    Affected Products

    Vendor
    Taskosaur
    Product
    Taskosaur

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High