Junglewise Threat Intelligence

CVE-2026-52781: OpenProject stored XSS in work package descriptions

CVE-2026-52781 · Severity: medium · CVSS 6.4 · Published 2026-06-26

Technologies: Opf OpenProject.

Executive brief

OpenProject is an open-source project management platform used for tracking tasks and team collaboration. A security flaw in how the software handles project descriptions allows an attacker to inject malicious code that can hijack a user's session. If exploited, this could lead to users being redirected to malicious websites or having their authenticated sessions manipulated without their knowledge.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in OpenProject due to an overly permissive HTML sanitizer that allows unrestricted 'data-*' attributes on '<macro>' elements. By injecting a 'data-controller="poll-for-changes"' attribute into a work package description, an attacker can trigger Stimulus.js to mount a controller. This controller fetches an attacker-controlled attachment and passes it to 'renderStreamMessage()', enabling the execution of arbitrary Turbo Stream actions. This can be used to perform actions like 'redirect_to' within the context of a victim's authenticated session. The vulnerability is fixed in versions 17.3.3 and 17.4.1.

Affected products

  • opf OpenProject < 17.3.3, >= 17.4.0 < 17.4.1

Timeline

  • 2026-06-08: advisory: Vendor advisory published on GitHub
  • 2026-06-26: disclosed: CVE published to NVD

References