OpenProject BlockNote Editor Extension ID Validation Vulnerability Allowing Arbitrary API Requests

Vulnerability

A vulnerability exists in the OpenProject BlockNote editor extension for collaborative documents, specifically in OpenProject versions 17.0.0 and 17.0.1. The issue arises because the extension fails to properly validate work package IDs, allowing attackers to create documents with links that can trigger arbitrary 'GET' requests to any URL within the OpenProject instance. This vulnerability was introduced in version 17.0.0 and could be exploited by manipulating work package IDs to bypass validation.

Impact

Exploitation of this vulnerability could lead to forced actions, content spoofing, and persistent denial-of-service within the OpenProject instance by manipulating work package IDs to make unauthorized API requests.

Remediation

Users can update to OpenProject version 17.0.2, which includes the patched BlockNote extension. If an immediate update is not possible, administrators can disable collaborative document editing in the OpenProject settings.

Added: Jan 28, 2026, 7:21 PM
Updated: Jan 28, 2026, 7:21 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
1.3
exploitability
5.7
remediation
8.3
relevance
2.4
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.