Offensive Sequence
Offensive Sequence
๐ŸŒ@offseq@infosec.exchangeยท
1 min read

๐Ÿšจ OpenProject CRITICAL XSS (CVE-2026-32703): Attackers with repo push access can inject persistent scripts via filenames, impacting all users viewing affected pages. Patch to 16.6.9/17.0.6/17.1.3/17.2.1+ now! radar.offseq.com/threat/cve-20

Critical threat: CVE-2026-32703: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scr

Marginalia