PT-2026-5180 · Openproject · Openproject+1

Scott Curtis

+1

·

Publicado

2026-01-28

·

Atualizado

2026-02-12

·

CVE-2026-24775

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenProject versions 17.0.0 through 17.0.1
Description OpenProject is a web-based project management software. A flaw exists in the BlockNote editor extension introduced in version 17.0.0, which allows mentioning OpenProject work packages within collaborative documents. The extension does not properly validate the work package ID used in API calls to retrieve work package details. This allows an attacker to create documents containing relative links that, when opened, can trigger arbitrary GET requests to any URL within the OpenProject instance. The API call is used to load work package details. The issue was addressed in version 0.0.22 of the op-blocknote-extensions component, included in OpenProject 17.0.2.
Recommendations Update to OpenProject version 17.0.2. If an immediate update is not possible, disable collaborative document editing in Settings -> Documents -> Real time collaboration -> Disable.

Exploit

Correção

DoS

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24775
GHSA-35C6-X276-2PVC

Produtos afetados

Openproject
Op-Blocknote-Extensions