CSS Injection Vulnerability in OpenProject Project Management Software
CVE-2026-44696
5.7MEDIUM
What is CVE-2026-44696?
OpenProject, an open-source project management tool, contains a vulnerability that allows authenticated users with write access to inject arbitrary CSS into text fields. Prior to version 17.4.0, the software's markdown rendering pipeline utilized a relaxed CSS sanitization configuration, permitting a wide range of CSS properties within inline styles. This oversight can lead to unintended styling alterations and potential exploitation of the application when an attacker leverages write permissions for malicious CSS injection. The issue has been addressed in OpenProject version 17.4.0, emphasizing the importance of upgrading to maintain security.
Affected Version(s)
openproject < 17.4.0
