
OpenProject is affected by SSRF and CSWSH in its Hocuspocus Synchronization Server (CVE-2026-24772). Upgrade to version 17.0.2. #OpenProject #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-24772-openproject-ssrf-cswsh
Post summary
OpenProject is vulnerable to SSRF and CSWSH in its Hocuspocus Synchronization Server (CVE‑2026‑24772). Users should upgrade to version 17.0.2 to address the issue.


