Offensive Sequence
Offensive Sequence
🌐@offseq@infosec.exchange·
1 min read

⚠️ CRITICAL: CVE-2026-32703 in OpenProject (<16.6.9, <17.0.6, <17.1.3, <17.2.1) enables persistent XSS via repo filenames. Attackers w/ push access can inject scripts — risk: session hijack, data theft. Patch now! radar.offseq.com/threat/cve-20

Critical threat: CVE-2026-32703: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scr

Marginalia