Technology · PyPI
pycti (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in pycti (PyPI): 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-35211, was published on 8 July 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 1
- Exploited in the wild
- 0
About pycti (PyPI)
pycti is a Python client library used to interact with the OpenCTI platform API.
Latest pycti (PyPI) vulnerabilities
- CVE-2026-35211: Filigran OpenCTI Code Injection in GraphQL APImediumCVSS 6.5EPSS 0.5%
- CVE-2026-35210: Filigran OpenCTI authorization bypass via synchronized-upsert headerhighCVSS 7.1EPSS 0.4%
- CVE-2026-21887: OpenCTI SSRF in Data Ingestion FeaturehighCVSS 7.7EPSS 0.2%
- CVE-2024-37155: OpenCTI GraphQL introspection restriction bypassmediumCVSS 6.5EPSS 0.5%
- CVE-2026-35212: OpenCTI XSS in email-message observable body renderinglowCVSS 3.1EPSS 0.3%
- CVE-2026-44730: OpenCTI privilege escalation in userEdit relationAddhighCVSS 7.2EPSS 0.5%
- CVE-2026-27960: OpenCTI privilege escalation and authentication bypass in APIcriticalCVSS 9.8EPSS 1.8%
- CVE-2026-39980: PYSEC-2026-2265 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables…lowCVSS 3.1EPSS 0.7%
- CVE-2026-21886: PYSEC-2026-117 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables…lowCVSS 3.1EPSS 0.2%
- CVE-2020-37044: PYSEC-2026-115 - OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint…lowCVSS 3.1EPSS 0.4%
- CVE-2020-37041: PYSEC-2026-114 - OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An…lowCVSS 3.1EPSS 1.0%
- CVE-2025-61782: PYSEC-2026-2264 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables…lowCVSS 3.1EPSS 0.3%
- CVE-2025-61781: PYSEC-2026-116 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables…lowCVSS 3.1EPSS 0.2%
- CVE-2025-46732: PYSEC-2025-181 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables…lowCVSS 3.1EPSS 0.2%
- CVE-2025-26621: PYSEC-2025-180 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables…lowCVSS 3.1EPSS 0.4%
- CVE-2025-24977: PYSEC-2025-179 - OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the…lowCVSS 3.1EPSS 0.8%
- CVE-2025-24887: PYSEC-2025-178 - OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before…lowCVSS 3.1EPSS 0.2%
- CVE-2024-45805: PYSEC-2024-298 - OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access…lowCVSS 3.1EPSS 0.3%
- CVE-2024-45404: PYSEC-2024-297 - OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the…lowCVSS 3.1EPSS 0.6%
- CVE-2024-26139: PYSEC-2024-296 - OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence…lowCVSS 3.1EPSS 0.4%
- CVE-2022-30290: PYSEC-2022-43186 - In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile…lowCVSS 3.1EPSS 1.0%
- CVE-2022-30289: PYSEC-2022-43185 - A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of…lowCVSS 3.1EPSS 0.5%
Most severe pycti (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-27960: OpenCTI privilege escalation and authentication bypass in APIcriticalCVSS 9.8EPSS 1.8%
- CVE-2026-21887: OpenCTI SSRF in Data Ingestion FeaturehighCVSS 7.7EPSS 0.2%
- CVE-2026-44730: OpenCTI privilege escalation in userEdit relationAddhighCVSS 7.2EPSS 0.5%
- CVE-2026-35210: Filigran OpenCTI authorization bypass via synchronized-upsert headerhighCVSS 7.1EPSS 0.4%
- CVE-2026-35211: Filigran OpenCTI Code Injection in GraphQL APImediumCVSS 6.5EPSS 0.5%
- CVE-2024-37155: OpenCTI GraphQL introspection restriction bypassmediumCVSS 6.5EPSS 0.5%
- CVE-2020-37041: PYSEC-2026-114 - OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An…lowCVSS 3.1EPSS 1.0%
- CVE-2022-30290: PYSEC-2022-43186 - In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile…lowCVSS 3.1EPSS 1.0%
- CVE-2025-24977: PYSEC-2025-179 - OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the…lowCVSS 3.1EPSS 0.8%
- CVE-2026-39980: PYSEC-2026-2265 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables…lowCVSS 3.1EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pycti.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pycti (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pycti, 26 September 2026.