Arbitrary File Write Vulnerability in OpenProject by OpenProject Foundation
CVE-2026-24685

9.4CRITICAL

Key Information:

Vendor

Opf

Vendor
CVE Published:
28 January 2026

What is CVE-2026-24685?

OpenProject, a popular open-source project management tool, has been found to have a vulnerability that allows unauthorized file writes through its repository diff download endpoint. When a user with sufficient permissions exploits this flaw by passing a specially crafted revision value, they can manipulate the underlying git show command to write files to any path accessible by the OpenProject process. This could lead to serious issues such as data loss and denial of service as attackers may overwrite critical files. The vulnerability affects versions prior to 16.6.6 and 17.0.2, which have since been patched. It is essential for users to update to these versions to safeguard their systems against potential abuse.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

openproject < 16.6.6 < 16.6.6

openproject >= 17.0.0, < 17.0.2 < 17.0.0, 17.0.2

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.