---
id: CVE-2026-39980
aliases:
  - PYSEC-2026-2265
  - GHSA-jv9r-jw2f-rhrf
title: >-
  OpenCTI is an open source platform for managing cyber threat intelligence
  knowledge and observables. Prior to 6.9.5, the safeEjs.ts file …
summary: >-
  OpenCTI is an open source platform for managing cyber threat intelligence
  knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not
  properly sanitize EJS templates. Users with the Manage customization
  capability can run arb…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
vendor: pycti
product: pycti
ecosystem: pip
affected:
  - pycti < 6.9.5
patched:
  - pycti 6.9.5
published: '2026-04-09'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2026-2265'
references:
  - url: 'https://github.com/OpenCTI-Platform/opencti/releases/tag/6.9.5'
  - url: >-
      https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-jv9r-jw2f-rhrf
tags:
  - osv
  - pip
epss: 0.00694
epssPercentile: 0.50912
ingestedAt: '2026-07-13T18:58:08.687Z'
---

## Overview

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arbitrary JavaScript in the context of the OpenCTI platform process during notifier template execution. This vulnerability is fixed in 6.9.5.

## Affected packages

- `pycti < 6.9.5`

## Remediation

Upgrade to a patched release:

- `pycti 6.9.5`
