


Perceptive Security
SOC/SIEM Consultancy

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality …
Published:
9 January 2026 at 23:00:00
Alert date:
10 January 2026 at 13:10:58
Source:
nvd.nist.gov
A Local File Read (LFR) vulnerability exists in OpenProject's work package PDF export functionality prior to version 16.6.4. Attackers can exploit the vulnerability by uploading a specially crafted SVG file disguised as a PNG attachment. When exported to PDF, the backend ImageMagick processing engine is triggered, allowing attackers to read arbitrary local files accessible to the application user. This includes sensitive files like /etc/passwd, project configuration files, and private project data. The attack requires permissions to upload attachments to containers that can be exported to PDF. The issue has been patched in version 16.6.4.
Technical details
Mitigation steps:
Affected products:
OpenProject
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-22600
https://github.com/opf/openproject/releases/tag/v16.6.4
https://github.com/opf/openproject/security/advisories/GHSA-m8f2-cwpq-vvhh
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
