OpenCTI GitHub Repositoryproduct
https://github.com/OpenCTI-Platform/opencti CVE-2020-37041
HIGH
OpenCTI 3.3.1 - Directory Traversal
Record summary
CVE-2020-37041 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can read arbitrary files from the filesystem by sending crafted GET requests with path traversal sequences (e.g., '../') in the URL. For example, requesting /static/css//../../../../../../../../etc/passwd returns the contents of /etc/passwd. This vulnerability was discovered by Raif Berkay Dincel and confirmed on Linux Mint and Windows 10.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 2, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
OpenCTIBrowse Filigran / OpenCTI | CVE List | 3.3.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBOpenCTI 3.3.1 - Directory TraversalExploitDB exploitby Raif Berkay DincelNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37041 ExploitDB-48595exploit
https://www.exploit-db.com/exploits/48595 OpenCTI Official Homepageproduct
https://www.opencti.io/ VulnCheck Advisory: OpenCTI 3.3.1 - Directory TraversalThird-party advisory
https://www.vulncheck.com/advisories/opencti-directory-traversal