Arbitrary File Write Vulnerability in OpenProject by OpenProject Foundation
CVE-2026-24685
What is CVE-2026-24685?
OpenProject, a popular open-source project management tool, has been found to have a vulnerability that allows unauthorized file writes through its repository diff download endpoint. When a user with sufficient permissions exploits this flaw by passing a specially crafted revision value, they can manipulate the underlying git show command to write files to any path accessible by the OpenProject process. This could lead to serious issues such as data loss and denial of service as attackers may overwrite critical files. The vulnerability affects versions prior to 16.6.6 and 17.0.2, which have since been patched. It is essential for users to update to these versions to safeguard their systems against potential abuse.
Affected Version(s)
openproject < 16.6.6 < 16.6.6
openproject >= 17.0.0, < 17.0.2 < 17.0.0, 17.0.2
