📦 Opencti

by Citeum

🔍 What is Opencti?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-24977

CRITICAL CVSS 9.1 May 5, 2025

OpenCTI versions before 6.4.11 contain a critical vulnerability where users with 'manage customizations' capability can execute arbitrary commands on the underlying infrastructure via webhook misuse. ...

CVE-2020-37041

HIGH CVSS 7.5 Jan 30, 2026

CVE-2020-37041 is a directory traversal vulnerability in OpenCTI 3.3.1 that allows unauthenticated attackers to read arbitrary files from the server filesystem. Attackers can exploit this by sending c...

CVE-2025-61781

HIGH CVSS 7.1 Jan 5, 2026

This vulnerability allows attackers to delete other users' workspaces in OpenCTI by exploiting an authorization flaw in the GraphQL mutation 'WorkspacePopoverDeletionMutation'. Any OpenCTI instance ru...

CVE-2024-26139

HIGH CVSS 8.3 May 23, 2024

This vulnerability in OpenCTI allows authenticated users with low privileges to escalate their permissions to administrative level through the profile edit functionality. Organizations using vulnerabl...

CVE-2025-61782

MEDIUM CVSS 5.4 Jan 7, 2026

OpenCTI versions before 6.8.3 contain an open redirect vulnerability in the SAML authentication callback endpoint. Attackers can manipulate the RelayState parameter to redirect users to malicious exte...

CVE-2025-24887

MEDIUM CVSS 6.3 Apr 30, 2025

OpenCTI versions 6.4.8 through 6.4.9 contain an authorization bypass vulnerability that allows authenticated users to modify restricted user attributes. Attackers can toggle external user flags, chang...