Executive brief
OpenProject is a web-based project management platform used for team collaboration and task tracking. A security flaw allows an attacker to trick the system into granting administrative privileges to a user account without the victim's knowledge. This could lead to a full takeover of the project management environment and unauthorized access to sensitive corporate data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in OpenProject's user management component. The flaw stems from how Turbo Drive auto-injects CSRF tokens into forms appended via Turbo Stream actions, combined with a 'dispatch_event' action that can trigger an automatic form submission. An attacker can exploit this by sending a malicious payload to the '/users/:id' endpoint using the 'user[admin]' POST parameter. Successful exploitation allows a low-privileged user to elevate their own or another user's privileges to administrator. The vulnerability is addressed in versions 17.3.3 and 17.4.1.
Affected products
- opf OpenProject < 17.3.3, >= 17.4.0 < 17.4.1
Timeline
- 2026-06-08: advisory: GitHub advisory published by vendor
- 2026-06-26: disclosed: NVD publication date
- 2026-06-26: patched: Fixes confirmed in versions 17.3.3 and 17.4.1