Junglewise Threat Intelligence

CVE-2024-37155: OpenCTI GraphQL introspection restriction bypass

CVE-2024-37155 · Severity: medium · CVSS 6.5 · Published 2026-06-22

Technologies: Filigran Pycti, Filigran Opencti. Vendors: PyPI.

Executive brief

OpenCTI, a platform for managing cyber threat intelligence, contains a flaw that allows users to bypass security restrictions on database queries. By manipulating the formatting of a request, an attacker can gain detailed information about the system's internal structure and capabilities. This information could be used to facilitate unauthorized data access or to launch a denial-of-service attack, potentially disrupting intelligence operations.

Technical details

A vulnerability in OpenCTI's 'secureIntrospectionPlugin' allows for the bypass of introspection query restrictions. The root cause is a flawed regex validation that fails to account for GraphQL queries where extra whitespace, carriage returns, and line feed characters have been removed. An unauthenticated remote attacker can exploit this by sending specially crafted, condensed GraphQL queries to the endpoint. Successful exploitation enables schema discovery, which can reveal unauthorized data access paths or be used to conduct Denial of Service (DoS) attacks through repeated complex queries. The issue is addressed in version 6.1.9.

Affected products

  • Filigran OpenCTI < 6.1.9
  • Filigran pycti < 6.1.9

Timeline

  • 2024-11-18: disclosed: Initial disclosure and NVD publication
  • 2024-11-18: patched: Fix released in version 6.1.9
  • 2026-06-22: advisory: GitHub Advisory published/updated

References

Related threats