Arbitrary File Write Vulnerability in OpenProject by OpenProject Foundation
CVE-2026-24685
What is CVE-2026-24685?
OpenProject, a popular open-source project management tool, has been found to have a vulnerability that allows unauthorized file writes through its repository diff download endpoint. When a user with sufficient permissions exploits this flaw by passing a specially crafted revision value, they can manipulate the underlying git show command to write files to any path accessible by the OpenProject process. This could lead to serious issues such as data loss and denial of service as attackers may overwrite critical files. The vulnerability affects versions prior to 16.6.6 and 17.0.2, which have since been patched. It is essential for users to update to these versions to safeguard their systems against potential abuse.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openproject < 16.6.6 < 16.6.6
openproject >= 17.0.0, < 17.0.2 < 17.0.0, 17.0.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
