CVE-2026-24685Disclosure(openproject / openproject)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openproject openproject systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability in OpenProject’s repository diff download endpoint (`/projects/:project_id/repository/diff.diff`) when rendering a single revision via git show. By supplying a specially crafted rev value (for example, `rev=--output=/tmp/poc.txt)`, an attacker can inject git show command-line options. When OpenProject executes the SCM command, Git interprets the attacker-controlled rev as an option and writes the output to an attacker-chosen path. As a result, any user with the `:browse_repository` permission on the project can create or overwrite arbitrary files that the OpenProject process user is permitted to write. The written contents consist of git show output (commit metadata and patch), but overwriting application or configuration files still leads to data loss and denial of service, impacting integrity and availability. The issue has been fixed in OpenProject 17.0.2 and 16.6.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openproject

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-01-28); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
openproject

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-01-28: 3Mentions · 2026-01-30: 1Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-28: 3Technical Details · 2026-01-30: 101-2801-30
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-283
Disclosure3
2026-01-301
Disclosure1
Full discourse4 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Command Injection in #OpenProject. #CVE-2026-24685 CVSS: 9.4. This command injection allows attackers to overwrite files leading to data loss and causing Denial of Service. #Patch #Patch #Patch

    Post summary

    A critical command injection CVE‑2026‑24685 in OpenProject has been announced, with high severity and potential for file overwrites, data loss, and denial of service, and a patch is implied to be available.

    02011304
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24685 Arbitrary File Write Vulnerability in OpenProject Repository Diff... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24685 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The text announces CVE-2026-24685 as an arbitrary file‑write vulnerability in OpenProject, but provides no PoC, exploit, active exploitation, patch, or false‑positive information.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24685 OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability in OpenProject’s … https://www.cve.org/CVERecord?id=CVE-2026-24685

    Post summary

    The text announces an arbitrary file write vulnerability in older OpenProject releases (CVE-2026-24685), without providing a PoC, exploit, or patch details.

    00000130
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-24685: OpenProject has Argument Injecti... Command injection in OpenProject's diff endpoint lets any repo browser write arbitrary files via crafted `rev` param—pe... https://zerodaysignal.com/vulnerability/CVE-2026-24685 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post reports a command injection flaw in OpenProject’s diff endpoint that allows writing arbitrary files via a crafted parameter. No patch, PoC, or active exploitation evidence is given.

    0000049
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprojectopenproject---

Explore more