Junglewise Threat Intelligence

CVE-2020-37044: PYSEC-2026-115 - OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can inject arbitrary Jav

CVE-2020-37044 · Severity: low · CVSS 3.1 · Published 2026-01-30

Technologies: pycti (PyPI). Vendors: PyPI.

Executive brief

OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can inject arbitrary JavaScript code by sending a crafted GET request with a malicious payload in the query string, leading to execution of JavaScript in the victim's browser. For example, a request to /graphql?'"--></style></scRipt><scRipt>alert('Raif_Berkay')</scRipt> will trigger an alert. This vulnerability was discovered by Raif Berkay Dincel and confirmed on Linux Mint and Windows 10.

Affected products

  • PyPI pycti

Related threats