CVE-2020-37041
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
30/01/2026
Last modified:
30/01/2026
Description
OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can read arbitrary files from the filesystem by sending crafted GET requests with path traversal sequences (e.g., '../') in the URL. For example, requesting /static/css//../../../../../../../../etc/passwd returns the contents of /etc/passwd. This vulnerability was discovered by Raif Berkay Dincel and confirmed on Linux Mint and Windows 10.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH



