← Vulnerability feed

Vulnerability record · CVE-2026-22600 · published 10 January 2026

CVE-2026-22600: Openproject information exposure vulnerability

Openproject · Openproject

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior to version 16.6.4. By uploading a specially crafted SVG file (disguised as a PNG) as a work package attachment, an attacker can exploit the backend image processing engine (ImageMagick). When the work package is exported to PDF, the backend attempts to resize the image, triggering the ImageMagick text: coder. This allows an attacker to read arbitrary local files that the application user has permissions to access (e.g., /etc/passwd, all project configuration files, private project data, etc.). The attack requires permissions to upload attachments to a container that can be exported to PDF, such as a work package. The issue has been patched in version 16.6.4. Those who are unable to upgrade may apply the patch manually.

9.1 CVSS 3.1 Critical EPSS 0.31% · top 78.7% CWE-200 · Information exposure
9.1CVSS 3.1 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior to version 16.6.4. By uploading a specially crafted SVG file (disguised as a PNG) as a work package attachment, an attacker can exploit the backend image processing engine (ImageMagick). When the work package is exported to PDF, the backend attempts to resize the image, triggering the ImageMagick text: coder. This allows an attacker to read arbitrary local files that the application user has permissions to access (e.g., /etc/passwd, all project configuration files, private project data, etc.). The attack requires permissions to upload attachments to a container that can be exported to PDF, such as a work package. The issue has been patched in version 16.6.4. Those who are unable to upgrade may apply the patch manually.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-22600 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-25763Openproject os command injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exis…EPSS 0.68%9.4CVE-2026-24685Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability …EPSS 0.36%9.0CVE-2026-24772Openproject insufficient verification of data authenticity vulnerabilityOpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced…EPSS 0.19%8.8CVE-2021-43830Openproject sql injection vulnerabilityOpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For a…EPSS 0.93%8.6CVE-2026-22601Openproject command injection vulnerabilityOpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execut…EPSS 0.37%8.1CVE-2026-34717Openproject sql injection vulnerabilityOpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operat…EPSS 0.45%8.1CVE-2019-11600OpenProject activities API SQL injection via id parameterOpenProject before 8.3.2 contains a SQL injection flaw in the activities API, reachable through the id parameter. An attacker can inject arbitrary SQ…EPSS 80%analysed8.1CVE-2017-11667Openproject insufficient session expiration vulnerabilityOpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leve…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2026-22600), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.