CVE Explorer
CVE-2026-24775
OpenProject is an open-source, web-based project management software. In the new editor for collaborative documents based on BlockNote, OpenProject maintainers added a custom extension in OpenProject version 17.0.0 that allows to mention OpenProject work packages in the document. To show work package details, the editor loads details about the work package via the OpenProject API. For this API call, the extension to the BlockNote editor did not properly validate the given work package ID to be o
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"openproject","vendor":"opf","versions":[{"status":"affected","version":">= 17.0.0, < 17.0.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:80b80eaeaefd0a85fc5fd5dc6f489f45c96b114d5b5052ee08905a3b9a3b0520 · sha256:043bd82eb2191207… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:80b80eaeaefd0a85fc5fd5dc6f489f45c96b114d5b5052ee08905a3b9a3b0520 · sha256:043bd82eb2191207… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:80b80eaeaefd0a85fc5fd5dc6f489f45c96b114d5b5052ee08905a3b9a3b0520 · sha256:043bd82eb2191207… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/opf/op-blocknote-extensions/releases/tag/v0.0.22","tags":["x_refsource_MISC"],"url":"https://github.com/opf/op-blocknote-extensions/releases/tag/v0.0.22"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:80b80eaeaefd0a85fc5fd5dc6f489f45c96b114d5b5052ee08905a3b9a3b0520 · sha256:043bd82eb2191207… · /containers/cna/references/1
{"name":"https://github.com/opf/openproject/security/advisories/GHSA-35c6-x276-2pvc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/opf/openproject/security/advisories/GHSA-35c6-x276-2pvc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:80b80eaeaefd0a85fc5fd5dc6f489f45c96b114d5b5052ee08905a3b9a3b0520 · sha256:043bd82eb2191207… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.