top of page
perceptive_background_267k.jpg

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality …

Published:

9 January 2026 at 23:00:00

Alert date:

10 January 2026 at 13:10:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

A Local File Read (LFR) vulnerability exists in OpenProject's work package PDF export functionality prior to version 16.6.4. Attackers can exploit the vulnerability by uploading a specially crafted SVG file disguised as a PNG attachment. When exported to PDF, the backend ImageMagick processing engine is triggered, allowing attackers to read arbitrary local files accessible to the application user. This includes sensitive files like /etc/passwd, project configuration files, and private project data. The attack requires permissions to upload attachments to containers that can be exported to PDF. The issue has been patched in version 16.6.4.

Technical details

Mitigation steps:

Affected products:

OpenProject

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page