CVE-2025-61782: Open Redirect in OpenCTI's SAML Authentication Flow
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnerability exists in the OpenCTI platform's SAML authentication endpoint (/auth/saml/callback). By manipulating the RelayState parameter, an attacker can force the server to issue a 302 redirect to any external URL, enabling phishing, credential theft, and arbitrary site redirection. This issue has been patched in version 6.8.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61782?
CVE-2025-61782 is categorized as a high severity vulnerability due to its potential for open redirect attacks.
How do I fix CVE-2025-61782?
To fix CVE-2025-61782, upgrade the OpenCTI platform to version 6.8.3 or later.
What is the impact of CVE-2025-61782?
The impact of CVE-2025-61782 allows attackers to manipulate the RelayState parameter, leading to open redirect vulnerabilities.
Which versions of OpenCTI are affected by CVE-2025-61782?
OpenCTI versions prior to 6.8.3 are affected by CVE-2025-61782.
Is CVE-2025-61782 specific to any authentication method?
Yes, CVE-2025-61782 specifically affects the SAML authentication endpoint of the OpenCTI platform.