Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-23625

OpenProject has stored XSS regression using attachments and script-src self
Back to all
CVE

CVE-2026-23625

OpenProject has stored XSS regression using attachments and script-src self

OpenProject is an open-source, web-based project management software. Versions 16.3.0 through 16.6.4 are affected by a stored cross-site scripting vulnerability in the Roadmap view. OpenProject’s roadmap view renders the “Related work packages” list for each version. When a version contains work packages from a different project (e.g., a subproject), the helper linktoworkpackage prepends package.project.tos to the link and returns the entire string with .htmlsafe. Because project names are user-controlled and no escaping happens before calling htmlsafe, any HTML placed in a subproject name is injected verbatim into the page. The underlying issue is mitigated in versions 16.6.5 and 17.0.0 by setting a X-Content-Type-Options: nosniff header, which was in place until a refactoring move to Rails standard content-security policy, which did not properly apply this header in the new configuration since OpenProject 16.3.0. Those who cannot upgrade their installations should ensure that they add a X-Content-Type-Options: nosniff header in their proxying web application server.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
8.7
-
3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23625.json, https://github.com/opf/openproject/releases/tag/v16.6.5, https://github.com/opf/openproject/releases/tag/v17.0.0, https://github.com/opf/openproject/security/advisories/GHSA-cvpq-cc56-gwxx, https://nvd.nist.gov/vuln/detail/CVE-2026-23625

Severity

8.7

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
8.7
EPSS Probability
0.00043%
EPSS Percentile
0.12984%
Introduced Version
c8e587a9592e6a4999eec6d16aa83eb11a89fba2
Fix Available
99112f321595e2fa5bd54727ceb2a20a07157af3

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading