CSS Injection Vulnerability in OpenProject Project Management Software
CVE-2026-44696

5.7MEDIUM

Key Information:

Vendor

Opf

Vendor
CVE Published:
26 June 2026

What is CVE-2026-44696?

OpenProject, an open-source project management tool, contains a vulnerability that allows authenticated users with write access to inject arbitrary CSS into text fields. Prior to version 17.4.0, the software's markdown rendering pipeline utilized a relaxed CSS sanitization configuration, permitting a wide range of CSS properties within inline styles. This oversight can lead to unintended styling alterations and potential exploitation of the application when an attacker leverages write permissions for malicious CSS injection. The issue has been addressed in OpenProject version 17.4.0, emphasizing the importance of upgrading to maintain security.

Affected Version(s)

openproject < 17.4.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.