CVE-2025-24977: OpenCTI has remote code execution and sensitive secrets exposed through web hook
OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability manage customizations can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal server side secrets by misusing the web-hooks. Since the malicious user gets a root shell inside a container this opens up the the infrastructure environment for further attacks and exposures. Version 6.4.11 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24977?
CVE-2025-24977 has a high severity rating due to its potential for unauthorized command execution and access to sensitive secrets.
How do I fix CVE-2025-24977?
To fix CVE-2025-24977, upgrade to OpenCTI version 6.4.11 or later, which contains the necessary security patches.
Who is affected by CVE-2025-24977?
Any user with the capability 'manage customizations' in OpenCTI versions prior to 6.4.11 is affected by CVE-2025-24977.
What risks are associated with CVE-2025-24977?
The risks associated with CVE-2025-24977 include unauthorized access to execute commands on the server and exposure of internal secrets.
What actions should I take if I cannot upgrade due to compatibility issues with CVE-2025-24977?
If you cannot upgrade due to compatibility issues, review your access controls and limit the 'manage customizations' capability to trusted users only.