CVE-2026-35212
Received Received - Intake
Cross-Site Scripting in OpenCTI Platform

Publication date: 2026-06-02

Last updated on: 2026-06-02

Assigner: GitHub, Inc.

Description
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering of email-message observable body data. The content of the body field isn't appropriately sanitized when being rendered. Does require user interaction but could be exploited by someone sharing stix or any of the ingester. This could lead to CSRF and then large scale session theft. Version 7.260227.0 contains a fix.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-02
Last Modified
2026-06-02
Generated
2026-06-03
AI Q&A
2026-06-03
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
opencti opencti to 7.260227.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects OpenCTI, an open source platform for managing cyber threat intelligence. Versions prior to 7.260227.0 are vulnerable to a Cross-Site Scripting (XSS) issue in the rendering of the email-message observable body data. Specifically, the content of the body field is not properly sanitized when displayed, which means malicious scripts could be executed if an attacker shares specially crafted data.

Exploitation requires user interaction, such as a user viewing the malicious content. The vulnerability could be exploited by someone sharing STIX data or through any ingester, potentially leading to Cross-Site Request Forgery (CSRF) and large scale session theft.

The issue was fixed in version 7.260227.0.


How can this vulnerability impact me? :

This vulnerability can lead to significant security risks including Cross-Site Request Forgery (CSRF) attacks and large scale session theft. An attacker could exploit the XSS vulnerability to execute malicious scripts in the context of a victim's browser, potentially hijacking user sessions and gaining unauthorized access to sensitive information or functionalities within the OpenCTI platform.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, upgrade OpenCTI to version 7.260227.0 or later, as this version contains the fix for the XSS issue in the rendering of email-message observable body data.

Additionally, be cautious with user interactions involving shared STIX data or any ingester, as exploitation requires user interaction.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability in OpenCTI allows for cross-site scripting (XSS) that can lead to cross-site request forgery (CSRF) and large scale session theft. Such security issues could potentially expose sensitive user data or session information.

However, the provided information does not specify any direct impact or implications regarding compliance with common standards and regulations such as GDPR or HIPAA.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart