CVE-2026-25763 | opf openproject up to 16.6.6/17.0.2 os command injection (GHSA-x37c-hcg5-r5m7 / EUVD-2026-5556)
A vulnerability, which was classified as critical, was found in opf openproject up to 16.6.6/17.0.2. Impacted is an unknown function. Such manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-25763. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.