pycti vulnerabilities
CVEs whose affected-version data names the pycti package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2024-37155Medium· 6.5OpenCTI May Bypass Introspection Restriction
OpenCTI May Bypass Introspection Restriction
CVE-2026-21887High· 7.7OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
CVE-2026-39980High· 7.2OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file …
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arb…
CVE-2025-61782Medium· 6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redi…
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnerability exists in the OpenCTI platform's SAML authentication endpoint (/auth/saml/callbac…