pycti has 4 CVEs on record. The median CVSS is 6.8 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
Worst active — by depth score
CVE-2026-21887High· 7.7OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature42CVE-2026-39980High· 7.2OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file …40CVE-2024-37155Medium· 6.5OpenCTI May Bypass Introspection Restriction36CVE-2025-61782Medium· 6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redi…34
pycti vulnerabilities
CVEs affecting pycti, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2024-37155Medium· 6.5OpenCTI May Bypass Introspection Restriction
OpenCTI May Bypass Introspection Restriction
CVE-2026-21887High· 7.7OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
CVE-2026-39980High· 7.2OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file …
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arb…
CVE-2025-61782Medium· 6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redi…
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnerability exists in the OpenCTI platform's SAML authentication endpoint (/auth/saml/callbac…