← العودة للجدول
CVE-2026-25763
CVE-2026-25763 — VulnCheck: OpenProject is an open-source, web-based project management software.
📅 2026-02-06
🔴 Critical 🔥 PoC Only VulnCheck PoC Research Vulnerability CVSS 9.9

📋 الوصف الكامل

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/projects/:project_id/repository/changes) when rendering the “latest changes” view via git log. By supplying a specially crafted rev value (for example, rev=--output=/tmp/poc.txt), an attacker can

💻 الأنظمة المتأثرة

VulnCheck: OpenProject is

⚠️ نوع التهديد

PoC Research

🔗 CVE ID

CVE-2026-25763

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v16.6.7

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←