VYPR
Medium severity6.5NVD Advisory· Published Mar 11, 2026· Updated Jun 17, 2026

CVE-2026-30234

CVE-2026-30234

Description

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions can upload a crafted .bcf archive where the value in markup.bcf is manipulated to contain an absolute or traversal local path (for example: /etc/passwd or ../../../../etc/passwd). During import, this untrusted value is used as file.path during attachment processing. As a result, local filesystem content can be read outside the intended ZIP scope. This results in an Arbitrary File Read (AFR) within the read permissions of the OpenProject application user. This vulnerability is fixed in 17.2.0.

Affected products

3
  • Opf/Openproject3 versions
    cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*range: <17.2.0
    • (no CPE)range: <17.2.0
    • (no CPE)range: < 17.2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.