Executive brief
OpenProject is an open-source project management platform used for tracking tasks and team collaboration. A security flaw in how the software handles project descriptions allows an attacker to inject malicious code that can hijack a user's session. If exploited, this could lead to users being redirected to malicious websites or having their authenticated sessions manipulated without their knowledge.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in OpenProject due to an overly permissive HTML sanitizer that allows unrestricted 'data-*' attributes on '<macro>' elements. By injecting a 'data-controller="poll-for-changes"' attribute into a work package description, an attacker can trigger Stimulus.js to mount a controller. This controller fetches an attacker-controlled attachment and passes it to 'renderStreamMessage()', enabling the execution of arbitrary Turbo Stream actions. This can be used to perform actions like 'redirect_to' within the context of a victim's authenticated session. The vulnerability is fixed in versions 17.3.3 and 17.4.1.
Affected products
- opf OpenProject < 17.3.3, >= 17.4.0 < 17.4.1
Timeline
- 2026-06-08: advisory: Vendor advisory published on GitHub
- 2026-06-26: disclosed: CVE published to NVD