CVE-2026-25763Disclosure(openproject / openproject)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openproject openproject systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/projects/:project_id/repository/changes) when rendering the “latest changes” view via git log. By supplying a specially crafted rev value (for example, rev=--output=/tmp/poc.txt), an attacker can inject git log command-line options. When OpenProject executes the SCM command, Git interprets the attacker-controlled rev as an option and writes the output to an attacker-chosen path. As a result, any user with the :browse_repository permission on the project can create or overwrite arbitrary files that the OpenProject process user is permitted to write. The written contents consist of git log output, but by crafting custom commits the attacker can still upload valid shell scripts, ultimately leading to RCE. The RCE lets the attacker create a reverse shell to the target host and view confidential files outside of OpenProject, such as /etc/passwd. This issue has been patched in versions 16.6.7 and 17.0.3.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openproject

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-06); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
openproject

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-06: 2Mentions · 2026-02-07: 1Mentions · 2026-06-18: 1PoC Mentioned / Linked · 2026-02-06: 1Patch / Workaround · 2026-02-07: 1Technical Details · 2026-02-06: 2Technical Details · 2026-02-07: 102-0602-0706-18
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-062
Disclosure2
2026-02-071
Patch1
2026-06-181
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25763 OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject… https://www.cve.org/CVERecord?id=CVE-2026-25763

    Post summary

    OpenProject versions prior to 16.6.7 and 17.0.3 are affected by an arbitrary file write vulnerability (CVE-2026-25763), as recorded on the CVE database.

    00010214
    56.5K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-25763: OpenProject Git Command Injection Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04lSk2w0

    Post summary

    The text appears to be an introductory announcement of the CVE‑2026‑25763 vulnerability, but it does not provide specific technical details, PoC, exploit code, or evidence of active exploitation. No patch or mitigation information is included.

    0000033
    31 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: OpenProject OS command injection (CVE-2026-25763) allows RCE via repository changes endpoint. Patch to 16.6.7/17.0.3+ ASAP! Impact: data breach, server takeover. Details: https://radar.offseq.com/threat/cve-2026-25763-cwe-78-improper-neutralization-of-s-f2d1f8d7 #O... https://t.co/ST6l9jwff7

    Post summary

    The tweet alerts to a critical OS command injection in OpenProject (CVE-2026-25763) that enables remote code execution and urges users to update to patch versions 16.6.7 or 17.0.3+.

    0000059
    268 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25763: Command Injection on OpenProject... Git parameter injection in OpenProject's repository endpoint turns browse permissions into full RCE via crafted commits... https://zerodaysignal.com/vulnerability/CVE-2026-25763 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-25763, a command injection flaw in OpenProject that can lead to full RCE via crafted commits, and provides a link to further details.

    00000102
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprojectopenproject---

Explore more