PatchSiren cyber security CVE debrief
CVE-2026-52781 opf CVE debrief
CVE-2026-52781 is a medium-severity vulnerability in OpenProject, an open-source project management software. The issue lies in the HTML sanitizer, which grants <macro> elements unrestricted data-* attributes via :data wildcard. This allows an attacker to inject malicious attributes, such as data-controller='poll-for-changes', into a work package description. Consequently, Stimulus.js mounts a controller that fetches an attacker-uploaded attachment and passes it to renderStreamMessage(). This enables the execution of arbitrary Turbo Stream actions, including redirect_to, in every victim's authenticated browser session. The vulnerability redirects victims to an attacker-controlled server. OpenProject versions 17.3.3 and 17.4.1 contain the fix for this issue.
- Vendor
- opf
- Product
- openproject
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-26
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-26
- Advisory updated
- 2026-06-29
Who should care
Administrators and users of OpenProject, especially those hosting their own instances, should be aware of this vulnerability. Given its medium severity and potential impact on authenticated users, defenders should prioritize patching. The vulnerability's exploitation requires a user to have permission to edit work package descriptions.
Technical summary
The HTML sanitizer in OpenProject, prior to versions 17.3.3 and 17.4.1, improperly handles <macro> elements, allowing unrestricted data-* attributes. An attacker can inject a data-controller attribute, triggering Stimulus.js to fetch and execute an attacker-uploaded attachment. This leads to the execution of arbitrary Turbo Stream actions in the context of authenticated users' browser sessions. The vulnerability's CVSS score is 6.4, indicating a medium severity level.
Defensive priority
Defenders should prioritize patching to prevent exploitation. Given the medium severity, immediate action is recommended, especially for instances exposed to untrusted users.
Recommended defensive actions
- Apply patches (17.3.3 or 17.4.1) to the OpenProject installation.
- Review and restrict editing permissions for work package descriptions.
- Monitor for suspicious activity related to work package descriptions and Turbo Stream actions.
- Implement additional security measures for user authentication and session management.
- Perform a thorough inventory check of OpenProject instances and their exposure.
Evidence notes
The CVE record and NVD detail provide official information about the vulnerability. A source reference from GitHub's security advisories offers additional context. However, the limited information available suggests that the vulnerability's scope and affected systems are not fully detailed. Further investigation and monitoring are necessary to understand the vulnerability's impact fully.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-52781 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-52781
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-52781 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52781
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/opf/openproject/security/advisories/GHSA-q33w-f822-hg8x
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.