top of page
perceptive_background_267k.jpg

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not p…

Published:

17 maart 2026 om 23:00:00

Alert date:

18 maart 2026 om 23:01:18

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

OpenProject, an open-source web-based project management software, contains a cross-site scripting (XSS) vulnerability in its Repositories module. The vulnerability affects versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1. The flaw occurs because the Repositories module fails to properly escape filenames displayed from repositories. Attackers with push access to the repository can exploit this by creating commits with filenames containing HTML code that gets injected into pages without proper sanitization. This enables persistent XSS attacks against all project members who access the repositories page to view changesets where maliciously crafted files were deleted. The vulnerability has been patched in versions 16.6.9, 17.0.6, 17.1.3, and 17.2.1.

Technical details

Mitigation steps:

Affected products:

OpenProject

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page