CVE-2026-24685 | opf openproject up to 16.6.5/17.0.1 /projects/ rev command injection (GHSA-74p5-9pr3-r6pw)
A vulnerability has been found in opf openproject up to 16.6.5/17.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /projects/. This manipulation of the argument rev causes command injection.
This vulnerability is registered as CVE-2026-24685. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.