Please find our statement on security in this document: https://www.openproject.org/docs/security-and-privacy/statement-on-security/
Security: opf/openproject
Security
SECURITY.md
-
View-only project member can restore cancelled recurring meeting occurrence via APIGHSA-3j89-3273-84f5 published
Jul 1, 2026 by oliverguentherModerate -
LDAP on-the-fly users bypass OpenProject brute-force protection before local user creationGHSA-vhfq-8mwf-g79w published
Jul 1, 2026 by oliverguentherModerate -
Cross-project authorization bypass allows deleting public Calendar and Team Planner queries from unauthorized projectsGHSA-jrx5-px3f-vfq4 published
Jun 10, 2026 by oliverguentherModerate -
Private work package data disclosure through single meeting agenda item APIGHSA-g387-6rm2-xw88 published
Jun 8, 2026 by oliverguentherModerate -
CSV exports allow spreadsheet formula injection leading to client-side data disclosureGHSA-fv8m-h8hc-57gq published
Jul 1, 2026 by oliverguentherHigh -
Journal diff endpoint bypasses object, journal, and field visibility checksGHSA-f2rx-x2qj-2hgj published
Jun 8, 2026 by oliverguentherHigh -
Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`GHSA-r85r-gjq2-f83r published
May 13, 2026 by oliverguentherCritical -
Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/renameGHSA-c767-34gh-gh2h published
May 13, 2026 by oliverguentherModerate -
Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirementsGHSA-px7f-cj9f-7m4m published
May 13, 2026 by oliverguentherModerate -
Improper Access Control on OpenProject through /projects/[projectName]/meetings via "invited_user_id" in GET parameter "filters" leads to user names disclosureGHSA-x7j3-cfgf-7mc4 published
May 13, 2026 by oliverguentherModerate
Learn more about advisories related to opf/openproject in the GitHub Advisory Database