# Redmine Patches XSS and Bypass Flaws

Published: 2026-08-26 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/1ec452b4-6c93-59a4-b826-62e3db5521e4/redmine-patches-xss-and-bypass-flaws

> Redmine fixed multiple vulnerabilities allowing remote XSS injection and security policy bypass; users should update to patched versions.

ANSSI (CERT-FR) issued an advisory summarizing multiple vulnerabilities disclosed by the Redmine project affecting versions prior to 6.0.11, 6.1.x before 6.1.4, and 7.x before 7.0.1. The flaws allow an attacker to perform indirect remote code injection (cross-site scripting) and to bypass security policy controls within the Redmine project management application.

No indication of active exploitation is provided in this advisory. Administrators running affected Redmine versions should consult the vendor's security advisory page and apply the available patches to remediate the identified issues. No CVE identifiers, indicators of compromise, or attribution details were included in the source bulletin.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1085

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1ec452b4-6c93-59a4-b826-62e3db5521e4/redmine-patches-xss-and-bypass-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
