cvedb.io
CVE-2025-24977
CRITICAL · CVSS 9.1
EPSS exploitation probability: 0%
Published 2025-05-05T17:18:47.397 · Last modified 2026-06-17T08:59:55.010

Summary

OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal server side secrets by misusing the web-hooks. Since the malicious user gets a root shell inside a container this opens up the the infrastructure environment for further attacks and exposures. Version 6.4.11 fixes the issue.

Affected products

citeum — opencti

Does this affect you?

Add your gear to cvedb and we'll alert you only when citeum ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.