Executive brief
OpenProject, a web-based project management platform, is vulnerable to a critical security flaw that allows an attacker to take complete control of the server. By manipulating the application's data caching system, an attacker can execute malicious commands remotely. This could lead to the theft of sensitive project data, total service disruption, or unauthorized access to the underlying corporate infrastructure.
Technical details
A vulnerability in OpenProject's cache store mechanism allows for cache poisoning, which can be escalated to Remote Code Execution (RCE). The flaw is rooted in improper input validation (CWE-20) within the caching component. An attacker on the same adjacent network can exploit this without any prior authentication or user interaction. By poisoning the cache, the attacker can inject and execute arbitrary code within the context of the application server. The issue has been addressed in versions 17.3.3 and 17.4.1.
Affected products
- opf OpenProject < 17.3.3, >= 17.4.0 < 17.4.1
Timeline
- 2026-06-08: advisory: GitHub Security Advisory published
- 2026-06-26: disclosed: NVD publication date