Arbitrary File Write Vulnerability in OpenProject by OPF
CVE-2026-25763
What is CVE-2026-25763?
OpenProject, a web-based project management solution, exhibits an arbitrary file write vulnerability in its repository changes endpoint, impacting versions before 16.6.7 and 17.0.3. The issue arises when a specially crafted 'rev' value is submitted, allowing attackers to insert command-line options into the git log execution path. This flaw permits unauthorized users with browse permissions to create or overwrite files on the server. Successfully exploiting this vulnerability can lead to remote code execution, enabling an attacker to execute shell scripts and potentially access sensitive files like '/etc/passwd'. Users are advised to update to the patched versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openproject < 16.6.7 < 16.6.7
openproject < 17.0.3 < 17.0.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
