CVE-2026-32703Disclosure(openproject / openproject)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openproject openproject systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This allowed an attacker with push access into the repository to create commits with filenames that included HTML code that was injected in the page without proper sanitation. This allowed a persisted XSS attack against all members of this project that accessed the repositories page to display a changeset where the maliciously crafted file was deleted. Versions 16.6.9, 17.0.6, 17.1.3, and 17.2.1 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openproject

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-03-19)
  • 5 total mentions across 2 days

Affected systems

Products
openproject

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-18: 2Mentions · 2026-03-19: 3Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 203-1803-19
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1Patch1
2026-03-193
Disclosure2General1
Full discourse5 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32703: OpenProjec... Push access + malicious filenames = persistent XSS against entire project teams - repository trust model completely broken #XSS #OpenProject. https://zerodaysignal.com/vulnerability/CVE-2026-32703 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑32703, outlining a persistent XSS flaw in OpenProject caused by push access and malicious filenames, without providing a PoC, exploit, or patch.

    0000063
    154 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32703 OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properl… https://www.cve.org/CVERecord?id=CVE-2026-32703

    Post summary

    The tweet lists the CVE and affected OpenProject versions but lacks further technical or operational details.

    00000142
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32703 Stored XSS in OpenProject Repositories Module via Malicio... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32703 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces a stored XSS vulnerability (CVE-2026-32703) in OpenProject's Repositories module, but provides no PoC, exploit, patch, or active exploitation evidence.

    0000045
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32703 - Critical OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames di... https://www.thehackerwire.com/vulnerability/CVE-2026-32703/ https://t.co/kT6CwuopCY

    Post summary

    The tweet announces CVE-2026-32703 affecting OpenProject versions prior to 16.6.9/17.0.6/17.1.3/17.2.1, noting an improper filename-escaping flaw in the Repositories module, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000041
    138 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32703: CRITICAL] Prior versions of OpenProject exposed to XSS attacks due to improper filename escaping in Repositories module-fixed in versions 16.6.9, 17.0.6, 17.1.3, 17.2.1. #cybersecurity#cve,CVE-2026-32703,#cybersecurity https://cvefind.com/CVE-2026-32703

    Post summary

    The message announces a critical XSS vulnerability in OpenProject with details on the affected versions and provides the fixed release versions, confirming a patch availability.

    0000042
    603 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprojectopenproject---
Appopenprojectopenproject17.2.0--

Explore more