{"schema_version":1,"title":"pycti (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in pycti (PyPI): 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-35211, was published on 8 July 2026.","url":"https://junglewise.ai/threats/technologies/pycti","json_url":"https://junglewise.ai/threats/technologies/pycti.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pycti","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":22,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":13},"latest":[{"cve":"CVE-2026-35211","cvss":6.5,"epss":0.0052,"slug":"cve-2026-35211-filigran-opencti-code-injection-in-graphql-api","title":"Filigran OpenCTI Code Injection in GraphQL API","severity":"medium","exploited":false,"published_at":"2026-07-08T21:16:48.63+00:00","url":"https://junglewise.ai/threats/cve-2026-35211-filigran-opencti-code-injection-in-graphql-api"},{"cve":"CVE-2026-35210","cvss":7.1,"epss":0.0035,"slug":"cve-2026-35210-filigran-opencti-authorization-bypass-via-synchronized-upsert","title":"Filigran OpenCTI authorization bypass via synchronized-upsert header","severity":"high","exploited":false,"published_at":"2026-07-08T21:16:48.487+00:00","url":"https://junglewise.ai/threats/cve-2026-35210-filigran-opencti-authorization-bypass-via-synchronized-upsert"},{"cve":"CVE-2026-21887","cvss":7.7,"epss":0.0021,"slug":"cve-2026-21887-opencti-ssrf-in-data-ingestion-feature","title":"OpenCTI SSRF in Data Ingestion Feature","severity":"high","exploited":false,"published_at":"2026-06-22T17:01:22+00:00","url":"https://junglewise.ai/threats/cve-2026-21887-opencti-ssrf-in-data-ingestion-feature"},{"cve":"CVE-2024-37155","cvss":6.5,"epss":0.0046,"slug":"cve-2024-37155-opencti-graphql-introspection-restriction-bypass","title":"OpenCTI GraphQL introspection restriction bypass","severity":"medium","exploited":false,"published_at":"2026-06-22T16:43:24+00:00","url":"https://junglewise.ai/threats/cve-2024-37155-opencti-graphql-introspection-restriction-bypass"},{"cve":"CVE-2026-35212","cvss":3.1,"epss":0.0025,"slug":"cve-2026-35212-opencti-xss-in-email-message-observable-body-rendering","title":"OpenCTI XSS in email-message observable body rendering","severity":"low","exploited":false,"published_at":"2026-06-02T22:16:16.727+00:00","url":"https://junglewise.ai/threats/cve-2026-35212-opencti-xss-in-email-message-observable-body-rendering"},{"cve":"CVE-2026-44730","cvss":7.2,"epss":0.0046,"slug":"cve-2026-44730-opencti-privilege-escalation-in-useredit-relationadd","title":"OpenCTI privilege escalation in userEdit relationAdd","severity":"high","exploited":false,"published_at":"2026-05-26T18:16:51.023+00:00","url":"https://junglewise.ai/threats/cve-2026-44730-opencti-privilege-escalation-in-useredit-relationadd"},{"cve":"CVE-2026-27960","cvss":9.8,"epss":0.0181,"slug":"cve-2026-27960-opencti-privilege-escalation-and-authentication-bypass-in-api","title":"OpenCTI privilege escalation and authentication bypass in API","severity":"critical","exploited":false,"published_at":"2026-05-05T19:16:21.38+00:00","url":"https://junglewise.ai/threats/cve-2026-27960-opencti-privilege-escalation-and-authentication-bypass-in-api"},{"cve":"CVE-2026-39980","cvss":3.1,"epss":0.0069,"slug":"cve-2026-39980-pysec-2026-2265-opencti-is-an-open-source-platform-for-managing","title":"PYSEC-2026-2265 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file doe","severity":"low","exploited":false,"published_at":"2026-04-09T18:17:02.203+00:00","url":"https://junglewise.ai/threats/cve-2026-39980-pysec-2026-2265-opencti-is-an-open-source-platform-for-managing"},{"cve":"CVE-2026-21886","cvss":3.1,"epss":0.0023,"slug":"cve-2026-21886-pysec-2026-117-opencti-is-an-open-source-platform-for-managing","title":"PYSEC-2026-117 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mut","severity":"low","exploited":false,"published_at":"2026-03-17T16:16:19.953+00:00","url":"https://junglewise.ai/threats/cve-2026-21886-pysec-2026-117-opencti-is-an-open-source-platform-for-managing"},{"cve":"CVE-2020-37044","cvss":3.1,"epss":0.0037,"slug":"cve-2020-37044-pysec-2026-115-opencti-3-3-1-is-vulnerable-to-a-reflected-cross","title":"PYSEC-2026-115 - OpenCTI 3.3.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the /graphql endpoint. An attacker can inject arbitrary Jav","severity":"low","exploited":false,"published_at":"2026-01-30T23:16:10.257+00:00","url":"https://junglewise.ai/threats/cve-2020-37044-pysec-2026-115-opencti-3-3-1-is-vulnerable-to-a-reflected-cross"},{"cve":"CVE-2020-37041","cvss":3.1,"epss":0.0104,"slug":"cve-2020-37041-pysec-2026-114-opencti-3-3-1-is-vulnerable-to-a-directory","title":"PYSEC-2026-114 - OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can read arbitrary file","severity":"low","exploited":false,"published_at":"2026-01-30T23:16:09.75+00:00","url":"https://junglewise.ai/threats/cve-2020-37041-pysec-2026-114-opencti-3-3-1-is-vulnerable-to-a-directory"},{"cve":"CVE-2025-61782","cvss":3.1,"epss":0.0026,"slug":"cve-2025-61782-pysec-2026-2264-opencti-is-an-open-source-platform-for-managing","title":"PYSEC-2026-2264 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirec","severity":"low","exploited":false,"published_at":"2026-01-07T18:15:51.223+00:00","url":"https://junglewise.ai/threats/cve-2025-61782-pysec-2026-2264-opencti-is-an-open-source-platform-for-managing"},{"cve":"CVE-2025-61781","cvss":3.1,"epss":0.0024,"slug":"cve-2025-61781-pysec-2026-116-opencti-is-an-open-source-platform-for-managing","title":"PYSEC-2026-116 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mut","severity":"low","exploited":false,"published_at":"2026-01-05T18:15:44.077+00:00","url":"https://junglewise.ai/threats/cve-2025-61781-pysec-2026-116-opencti-is-an-open-source-platform-for-managing"},{"cve":"CVE-2025-46732","cvss":3.1,"epss":0.0021,"slug":"cve-2025-46732-pysec-2025-181-opencti-is-an-open-source-platform-for-managing","title":"PYSEC-2025-181 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnera","severity":"low","exploited":false,"published_at":"2025-07-18T15:15:27.2+00:00","url":"https://junglewise.ai/threats/cve-2025-46732-pysec-2025-181-opencti-is-an-open-source-platform-for-managing"},{"cve":"CVE-2025-26621","cvss":3.1,"epss":0.0041,"slug":"cve-2025-26621-pysec-2025-180-opencti-is-an-open-source-platform-for-managing","title":"PYSEC-2025-180 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.5.2, any user with t","severity":"low","exploited":false,"published_at":"2025-05-19T16:15:28.56+00:00","url":"https://junglewise.ai/threats/cve-2025-26621-pysec-2025-180-opencti-is-an-open-source-platform-for-managing"},{"cve":"CVE-2025-24977","cvss":3.1,"epss":0.0082,"slug":"cve-2025-24977-pysec-2025-179-opencti-is-an-open-cyber-threat-intelligence-cti","title":"PYSEC-2025-179 - OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` ca","severity":"low","exploited":false,"published_at":"2025-05-05T17:18:47.397+00:00","url":"https://junglewise.ai/threats/cve-2025-24977-pysec-2025-179-opencti-is-an-open-cyber-threat-intelligence-cti"},{"cve":"CVE-2025-24887","cvss":3.1,"epss":0.0024,"slug":"cve-2025-24887-pysec-2025-178-opencti-is-an-open-source-cyber-threat","title":"PYSEC-2025-178 - OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be","severity":"low","exploited":false,"published_at":"2025-04-30T19:15:55.07+00:00","url":"https://junglewise.ai/threats/cve-2025-24887-pysec-2025-178-opencti-is-an-open-source-cyber-threat"},{"cve":"CVE-2024-45805","cvss":3.1,"epss":0.0029,"slug":"cve-2024-45805-pysec-2024-298-opencti-is-an-open-source-cyber-threat","title":"PYSEC-2024-298 - OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that can only be accessed b","severity":"low","exploited":false,"published_at":"2024-12-26T22:15:15.083+00:00","url":"https://junglewise.ai/threats/cve-2024-45805-pysec-2024-298-opencti-is-an-open-source-cyber-threat"},{"cve":"CVE-2024-45404","cvss":3.1,"epss":0.0059,"slug":"cve-2024-45404-pysec-2024-297-opencti-is-an-open-source-cyber-threat","title":"PYSEC-2024-297 - OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does n","severity":"low","exploited":false,"published_at":"2024-12-12T02:02:09.53+00:00","url":"https://junglewise.ai/threats/cve-2024-45404-pysec-2024-297-opencti-is-an-open-source-cyber-threat"},{"cve":"CVE-2024-26139","cvss":3.1,"epss":0.004,"slug":"cve-2024-26139-pysec-2024-296-opencti-is-an-open-source-platform-allowing","title":"PYSEC-2024-296 - OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack o","severity":"low","exploited":false,"published_at":"2024-05-23T12:15:09.53+00:00","url":"https://junglewise.ai/threats/cve-2024-26139-pysec-2024-296-opencti-is-an-open-source-platform-allowing"},{"cve":"CVE-2022-30290","cvss":3.1,"epss":0.0098,"slug":"cve-2022-30290-pysec-2022-43186-in-opencti-through-5-2-4-a-broken-access-control","title":"PYSEC-2022-43186 - In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker can abuse the ident","severity":"low","exploited":false,"published_at":"2022-07-05T13:15:08.427+00:00","url":"https://junglewise.ai/threats/cve-2022-30290-pysec-2022-43186-in-opencti-through-5-2-4-a-broken-access-control"},{"cve":"CVE-2022-30289","cvss":3.1,"epss":0.0052,"slug":"cve-2022-30289-pysec-2022-43185-a-stored-cross-site-scripting-xss-vulnerability","title":"PYSEC-2022-43185 - A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2.4. An attacker can","severity":"low","exploited":false,"published_at":"2022-07-05T12:15:08+00:00","url":"https://junglewise.ai/threats/cve-2022-30289-pysec-2022-43185-a-stored-cross-site-scripting-xss-vulnerability"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"pycti (PyPI)","slug":"pycti","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/pycti/","repo_url":"https://github.com/OpenCTI-Platform/client-python","description":"pycti is a Python client library used to interact with the OpenCTI platform API.","url":"https://junglewise.ai/threats/technologies/pycti"},"most_severe":[{"cve":"CVE-2026-27960","cvss":9.8,"epss":0.0181,"slug":"cve-2026-27960-opencti-privilege-escalation-and-authentication-bypass-in-api","title":"OpenCTI privilege escalation and authentication bypass in API","severity":"critical","exploited":false,"published_at":"2026-05-05T19:16:21.38+00:00","url":"https://junglewise.ai/threats/cve-2026-27960-opencti-privilege-escalation-and-authentication-bypass-in-api"},{"cve":"CVE-2026-21887","cvss":7.7,"epss":0.0021,"slug":"cve-2026-21887-opencti-ssrf-in-data-ingestion-feature","title":"OpenCTI SSRF in Data Ingestion Feature","severity":"high","exploited":false,"published_at":"2026-06-22T17:01:22+00:00","url":"https://junglewise.ai/threats/cve-2026-21887-opencti-ssrf-in-data-ingestion-feature"},{"cve":"CVE-2026-44730","cvss":7.2,"epss":0.0046,"slug":"cve-2026-44730-opencti-privilege-escalation-in-useredit-relationadd","title":"OpenCTI privilege escalation in userEdit relationAdd","severity":"high","exploited":false,"published_at":"2026-05-26T18:16:51.023+00:00","url":"https://junglewise.ai/threats/cve-2026-44730-opencti-privilege-escalation-in-useredit-relationadd"},{"cve":"CVE-2026-35210","cvss":7.1,"epss":0.0035,"slug":"cve-2026-35210-filigran-opencti-authorization-bypass-via-synchronized-upsert","title":"Filigran OpenCTI authorization bypass via synchronized-upsert header","severity":"high","exploited":false,"published_at":"2026-07-08T21:16:48.487+00:00","url":"https://junglewise.ai/threats/cve-2026-35210-filigran-opencti-authorization-bypass-via-synchronized-upsert"},{"cve":"CVE-2026-35211","cvss":6.5,"epss":0.0052,"slug":"cve-2026-35211-filigran-opencti-code-injection-in-graphql-api","title":"Filigran OpenCTI Code Injection in GraphQL API","severity":"medium","exploited":false,"published_at":"2026-07-08T21:16:48.63+00:00","url":"https://junglewise.ai/threats/cve-2026-35211-filigran-opencti-code-injection-in-graphql-api"},{"cve":"CVE-2024-37155","cvss":6.5,"epss":0.0046,"slug":"cve-2024-37155-opencti-graphql-introspection-restriction-bypass","title":"OpenCTI GraphQL introspection restriction bypass","severity":"medium","exploited":false,"published_at":"2026-06-22T16:43:24+00:00","url":"https://junglewise.ai/threats/cve-2024-37155-opencti-graphql-introspection-restriction-bypass"},{"cve":"CVE-2020-37041","cvss":3.1,"epss":0.0104,"slug":"cve-2020-37041-pysec-2026-114-opencti-3-3-1-is-vulnerable-to-a-directory","title":"PYSEC-2026-114 - OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can read arbitrary file","severity":"low","exploited":false,"published_at":"2026-01-30T23:16:09.75+00:00","url":"https://junglewise.ai/threats/cve-2020-37041-pysec-2026-114-opencti-3-3-1-is-vulnerable-to-a-directory"},{"cve":"CVE-2022-30290","cvss":3.1,"epss":0.0098,"slug":"cve-2022-30290-pysec-2022-43186-in-opencti-through-5-2-4-a-broken-access-control","title":"PYSEC-2022-43186 - In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker can abuse the ident","severity":"low","exploited":false,"published_at":"2022-07-05T13:15:08.427+00:00","url":"https://junglewise.ai/threats/cve-2022-30290-pysec-2022-43186-in-opencti-through-5-2-4-a-broken-access-control"},{"cve":"CVE-2025-24977","cvss":3.1,"epss":0.0082,"slug":"cve-2025-24977-pysec-2025-179-opencti-is-an-open-cyber-threat-intelligence-cti","title":"PYSEC-2025-179 - OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` ca","severity":"low","exploited":false,"published_at":"2025-05-05T17:18:47.397+00:00","url":"https://junglewise.ai/threats/cve-2025-24977-pysec-2025-179-opencti-is-an-open-cyber-threat-intelligence-cti"},{"cve":"CVE-2026-39980","cvss":3.1,"epss":0.0069,"slug":"cve-2026-39980-pysec-2026-2265-opencti-is-an-open-source-platform-for-managing","title":"PYSEC-2026-2265 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file doe","severity":"low","exploited":false,"published_at":"2026-04-09T18:17:02.203+00:00","url":"https://junglewise.ai/threats/cve-2026-39980-pysec-2026-2265-opencti-is-an-open-source-platform-for-managing"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}