Please find our statement on security in this document: https://www.openproject.org/docs/security-and-privacy/statement-on-security/
Security: opf/openproject
Security
SECURITY.md
-
Repository files are served with the MIME type allowing them to be used to bypass Content Security PolicyGHSA-p423-72h4-fjvp published
Mar 16, 2026 by oliverguentherCritical -
SQL Injection via Custom Field Name can be chained to Remote Code ExecutionGHSA-jqhf-rf9x-9rhx published
Mar 16, 2026 by oliverguentherCritical -
2FA OTP Verification Missing Rate Limiting (CWE-307)GHSA-234r-45m2-w6cv published
Apr 15, 2026 by oliverguentherHigh -
Blind SSRF on OpenProject instance via webhooks, and through /admin/test_email via POST request leads to internal network reconnaissanceGHSA-9wr7-j98g-2jh3 published
Mar 11, 2026 by machisujiLow -
Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package SubjectsGHSA-p9gq-hrgh-2645 published
May 13, 2026 by oliverguentherModerate -
Permission Check bypass on Budget deletion allows reassignment of WorkPackages into other budgetsGHSA-gpvh-g967-g4h8 published
Mar 11, 2026 by machisujiModerate -
Users that are not project members can be used to calculate Labor Budget, leaking their global hourly rateGHSA-p747-569x-3v3f published
Mar 11, 2026 by machisujiModerate -
OpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Read (AFR)GHSA-q8c5-vpmm-xrxv published
Mar 11, 2026 by machisujiModerate -
Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltrationGHSA-j9q2-49mp-hmq5 published
May 13, 2026 by oliverguentherModerate -
Insecure Direct Object Reference in Project Storage Administrition Theft & Pre-Auth Remote Folder DeletionGHSA-v8cr-7x8f-78mq published
Feb 26, 2026 by klaustopherCritical
Learn more about advisories related to opf/openproject in the GitHub Advisory Database