NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3210 most downloaded on PyPI
Python API client for OpenCTI.
Last release today
17 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 53 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
449 releases · first in 2019
fix(security/groups): update skeleton loading to only render if password_valid_until is defined (#17131) by @scarletmerlin123 in https://github.com/Op
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260710.0...7.260715.0
One column per quarter.
Full Changelog: 7.260710.0...7.260715.0
feat(accessibility): add aria-labels to IconButtons where necessary, restructure to utilize tooltips to pass label where possible (#16886) by @scarlet
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260706.0...7.260710.0
Full Changelog: 7.260706.0...7.260710.0
fix(connector): handle connector deprecated fields (#16249) by @esrevi in https://github.com/OpenCTI-Platform/opencti/pull/16529
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260701.0...7.260706.0
chore(ci): auto label migration on PRs (#16358) by @aHenryJard in https://github.com/OpenCTI-Platform/opencti/pull/16359
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260626.0...7.260701.0
feat(form-intake): allow to use entity lookup with on-the-fly creation when user has only createupdate (#16469) by @OctaveLaventure in https://github.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260624.0...7.260626.0
fix(client-python): upgrade starlette to >=1.3.0 to fix CVE-2026-54282 (#16731) by @xfournet in https://github.com/OpenCTI-Platform/opencti/pull/16732
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260619.0...7.260624.0
> Please note that the migration introduced with https://github.com/OpenCTI-Platform/opencti/pull/16666 to fix duplicated attack patterns might take a
Please note that the migration introduced with https://github.com/OpenCTI-Platform/opencti/pull/16666 to fix duplicated attack patterns might take a significant amount of time, depending on the volume of data to update.
withCancel wrapper leaks PubSubAsyncIterator on cancellationFull Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260615.0...7.260619.0
chore(deps): update yarn monorepo to v4.16.0 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/16418
entity_type filter unconditionally expands to parent_types, leaking History/Activity documents into concrete-type queriesFull Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260609.0...7.260615.0
fix(sso): Remove message announcing deprecation of environement (#16223) by @ValentinBouzinFiligran in https://github.com/OpenCTI-Platform/opencti/pul…
buildCompleteUsers issues an un-chunked contact_information query that exceeds Lucene max_clause_count, breaking user-cache build at scaleFull Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260604.0...7.260609.0
[backend/frontend] Support agent-generated file downloads from XTM One (#16294) by @SamuelHassine in https://github.com/OpenCTI-Platform/opencti/pull/
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260529.0...7.260604.0
[backend] Upgrade opentelemetry deps to new major version (#16065) by @fellowseb in https://github.com/OpenCTI-Platform/opencti/pull/15500
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260527.0...7.260529.0
[backend/frontend] add ability to order drafts by Author, assignee and participant (#15959) by @frapuks in https://github.com/OpenCTI-Platform/opencti
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260522.0...7.260527.0
[backend] Sharing saved filters APIs (#11624) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/16044
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260521.0...7.260522.0
[backend/frontend] Fix public dashboard URI key not generated for non-Latin names (#16005) by @marieflorescontact in https://github.com/OpenCTI-Platfo
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260520.0...7.260521.0
[backend] Standardize authentication management for feeds and synchronizers (#15682) by @ludovic in https://github.com/OpenCTI-Platform/opencti/pull/1
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260515.0...7.260520.0
[frontend] Display create draft button under right capabilities (#15768) by @frapuks in https://github.com/OpenCTI-Platform/opencti/pull/15828
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260513.0...7.260515.0
[deps] Update dependency openai to v6.37.0 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/15920
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260512.0...7.260513.0
[deps] Update dependency @langchain/core to v1.1.45 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/15918
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260510.0...7.260512.0
[frontend/backend] on session timeout, user is logout (#15252) by @esrevi in https://github.com/OpenCTI-Platform/opencti/pull/15867
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260507.0...7.260510.0
[deps] Update dependency @langchain/core to v1.1.44 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/15781
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260506.0...7.260507.0
[backend/frontend] Fix marking attribute for History&Activity widgets (#15770) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/15772
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260430.0...7.260506.0
[backend] remove managers from mandatory codecov (#15742) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/15743
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260428.0...7.260430.0
[deps] Update dependency @filigran/chatbot to v3.2.0 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/15265
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260423.0...7.260428.0
[deps] Update dependency lru-cache to v11.3.5 by @renovate[bot] in https://github.com/OpenCTI-Platform/opencti/pull/15541
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260422.0...7.260423.0
[backend] added a timeout to rabbitMQ metrics queries (#12680) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/15438
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260417.0...7.260422.0
[frontend/backend] Add creators, creation date and modification date for Playbooks (#13943) by @Archidoit in https://github.com/OpenCTI-Platform/openc
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260416.0...7.260417.0
[frontend] SCO colors are now different based on their name (#15421) by @esrevi in https://github.com/OpenCTI-Platform/opencti/pull/15420
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260409.0...7.260416.0
[doc] Add a breaking change entry (#15218) by @aHenryJard in https://github.com/OpenCTI-Platform/opencti/pull/15307
FINTEL_FOR_ENTITY feature flag (#15210) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/15368Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260401.0...7.260409.0
[backend] Changed vulnerabilities to vulnerability in security coverage vocabulary (#14676) by @MTorbay-Filigran in https://github.com/OpenCTI-Platfor…
content to all containers (#12530) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/15146Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260326.0...7.260401.0
[frontend] migrate react-grid-layout from v1 to v2 (#14955) by @ludovic in https://github.com/OpenCTI-Platform/opencti/pull/14959
['entity_type'] — regression from UI design system refactorx_opencti_negative field is not updated on upsertFull Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260318.0...7.260326.0
[frontend] fix “has” relationship in the vulnerabilities menu (#15036) by @CelineSebe in https://github.com/OpenCTI-Platform/opencti/pull/15038
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260317.0...7.260318.0
[backend] Add relationships to support vulnerability impact analysis (#14338) by @CelineSebe in https://github.com/OpenCTI-Platform/opencti/pull/14712
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260309.0...7.260317.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[backend] Fix dashboard export failing with dynamicRegardingOf filters (#14539, #14527) by @SamuelHassine in https://github.com/OpenCTI-Platform/openc
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260306.1...7.260309.0
[backend] fix OpenIDConnect when token are not valid JWT (#14839) by @xfournet in https://github.com/OpenCTI-Platform/opencti/pull/14840
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260306.0...7.260306.1
[doc] Fix typos, spelling mistakes, and grammar issues across docs/ folder by @Copilot in https://github.com/OpenCTI-Platform/opencti/pull/14627
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260305.0...7.260306.0
[frontend] add revoked to vulnerability edition form (#14106) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/14138
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260227.0...7.260305.0
docs: fix broken and incorrect links in documentation by @Copilot in https://github.com/OpenCTI-Platform/opencti/pull/14587
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/7.260224.0...7.260227.0
…of interest such as IOCs, threat actors, and vulnerabilities. It then enriches them with contextual cards displaying information already present in yo…
Dear community, we're excited to announce the launch of OpenCTI version 7 (7.260224.0) 🥳. We packed a lot of content on this release, and you will see important changes when using OpenCTI. This changes imply breaking changes.
[!IMPORTANT] Make sure you read the Breaking Change section at the bottom of this Release Note.
We are also introducing a new version naming convention matching our current ability to deliver releases. All of it make it worth to jump into the 7 digit 🙂
An LTS license allows Entreprise Edition users to stay on a LTS version for up to one year while receiving backported fixes for critical bugs and security issues. This licence is available to those of our On-Prem EE customers that might be tied by mandatory testing framework before going to production and that cannot match our current rythm of release.
We plan to release two LTS versions per year, giving you the option to align feature upgrades with a predictable twice‑yearly cycle.
You will find all information about the new Product Lifecycle of OpenCTI, including the new naming convention and the new Long Term Support offering, to this documentation page: https://docs.opencti.io/latest/administration/product-life-cycle/
🍬 Important to note, OpenCTI v7 introduces first steps towards a full new UI Design System, helping users to focus on what matters & reduce the cognitive load. From the start, you will see the difference!
This Major release is also full of improvements and new features, focusing on solving key pain points and unlocking new use cases, including:
In version 7 you will now be able to manage your SSO authentication mechanism via the OpenCTI UI (if your platform is Entreprise edition). This means that you will no longer need to update the configuration file (cross your fingers and hope) and reload the app to make changes. For all existing, your configurations will now be available via the UI and you can easily update and add new configurations as you require. This feature allows you be self sufficient, regardless of your deployment type (on-premise, SaaS).
[!IMPORTANT] As announced in December 2025, SSO will fall under Entreprise Edition license in Version 7. This will mean that any Community Edition platforms that migrate to version 7.0.0 and onwards will not be able to login using SSO configured previously. Moving SSO to the Enterprise Edition ensures that Filigran can sustainably maintain and continuously improve OpenCTI over the long term, while keeping investment strong in the Community Edition's core capabilities and responsibly managing the resources required to run a secure, high-quality open-source security platform.*
Almost all existing authentication methods will remain available in the UI. Configuration defined in files will still exist but migrated into the database and used for login. For migration details, authentication setup guidance, or troubleshooting, please refer to the links below.
We've redesigned API token management in OpenCTI for better control, security, and visibility.
What's changed
Existing tokens will continue working. We recommend reviewing tokens and transitioning to the new model for expiration controls and per-integration isolation.
Draft mode now supports granular capability controls, separate from platform-wide permissions.
This lets you restrict analysts to creating/updating data in drafts only, while others approve and validate—securing your platform and preventing unwanted changes.
This is the first step toward a validation workflow leveraging the draft workspace—more updates coming soon.
User visibility ensures no data leakage across organizations (available since 6.9.11)
The platform interface has been completely modernized with the V7 design system. This comprehensive redesign touches nearly every visual element you interact with: buttons, navigation, drawers, cards, labels, header, and many other components.
The goal? Create a lighter, cleaner interface that helps you work faster and with less visual noise.
Key improvements include:
This foundational redesign addresses previous challenges with visual complexity and outdated patterns, transforming the interface into a modern, efficient workspace that helps security teams focus on what matters most: Threat intelligence and Analysis.
We're introducing a browser extension that bridges any web page directly with your OpenCTI platform, eliminating the need to switch between your browser and OpenCTI when collecting threat intelligence.
How it works:
The extension is available for all major browsers: Firefox, Chrome, Edge, and Safari.
What this solves:
Analysts spend significant time browsing the web for threat intelligence across blogs, social media, advisories, and other sources. When they find relevant content, they face a tedious workflow: checking if the information already exists in OpenCTI, then manually creating objects and relationships, or converting the page to PDF for AI-assisted extraction.
This extension eliminates that friction. You stay on the page you're reading while the extension handles detection, enrichment, and ingestion. No more context switching, no more manual modeling, no more PDF conversions.
Community vs. Enterprise capabilities:
This extension transforms casual web browsing into an active intelligence collection workflow, making it effortless to capitalize on threat intelligence wherever you find it.
Playbooks can now remove specific labels and markings from entities, even if those values weren't added by the playbook itself. Previously, you could only remove values that were added within the same playbook execution, forcing manual cleanup for pre-existing labels or markings. This enhancement eliminates that limitation, allowing you to fully automate label and marking management without manual intervention.
You can now manually trigger playbooks on any entity type. A new "Enroll in playbook" button allows analysts to initiate automated workflows on-demand for specific entities. The interface displays available playbooks filtered by entity compatibility and trigger conditions, enabling one-click manual enrollment.
🔗 Connectors & Integrations (CE)
This milestone brings a significant expansion of the OpenCTI connector ecosystem, with new integrations and meaningful improvements across the board.
External Import
Enrichment
Third-Party Applications
Additionally, a large set of connectors has been added to the OpenCTI catalog with one-click deployment support: DNSTwist, Red Flag Domains, Microsoft Sentinel Incidents, Valhalla, MITRE Atlas, MalwareBazaar, Wiz Cloud Landscape, URLHaus, MISP, CPE, Recorded Future Enrichment, DISARM, Phishunt, AbuseIPDB Blacklist, MISP Feed, Dragos, Microsoft Defender Intel, Silobreaker, Microsoft Sentinel Intel, Intel471, and First EPSS.
For all the breaking changes, please have a look at our documentation: https://docs.opencti.io/latest/deployment/breaking-changes/?h=breaking+change.
api_token per user with a modern multi-token system featuring HMAC-hashed storage, expiration policies, per-token usage tracking, and capability-based access control. Connector-to-platform authentication is upgraded from raw token passthrough to JWT-based mutual authentication using platform-derived Ed25519 key pairs. All existing tokens are automatically migrated to the new system. After migration existing tokens will be encrypted and so no longer be retrievable by the user.User.api_token → User.api_tokens (type changed from String! to [ApiToken!]!)MeUser.api_token → MeUser.api_tokensmeTokenRenew mutation removedUserEditMutations.tokenRenew mutation removedMeUser.api_token → MeUser.api_tokenstoken_renew() method removed, replaced by create_token() / remove_token()- Env variable: APP__ENCRYPTION_KEY=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Configuration file: app { encryption_key = "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" }
content attribute to fintel (#12530) by @delemaf in https://github.com/OpenCTI-Platform/opencti/pull/13702Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.22...7.260224.0
[backend/frontend] fix users visibility outside org segreg (#15158) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/15173
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.28...6.9.29
*No changelog for this release.*
No changelog for this release.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.27...6.9.28
[backend] backport of add sha256 to file metadata & use sha256 to check for duplicate upload (#14877) by @JeremyCloarec in https://github.com/OpenCTI-
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.26...6.9.27
[backend/frontend] Fix drawer visble for all users for 6.9.x (#14895) by @xfournet in https://github.com/OpenCTI-Platform/opencti/pull/14907
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.25...6.9.26
#### Enhancements: * #14891 : Update 3rd party dependencies on 6.9.x Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.24...6.9.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.24...6.9.25
[backend] Stream consumers should only return valid and ongoing consumers (#14816) by @Archidoit in https://github.com/OpenCTI-Platform/opencti/pull/1
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.23...6.9.24
[ci] do not produce prerelease build and docker images by @labo-flg in https://github.com/OpenCTI-Platform/opencti/pull/14618
Bug fixes
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.22...6.9.23
[backend] fix buggy history events (#14537) by @xfournet in https://github.com/OpenCTI-Platform/opencti/pull/14538
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.21...6.9.22
[Doc] Fix some typos by @romain-filigran in https://github.com/OpenCTI-Platform/opencti/pull/14520
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.20...6.9.21
*No changelog for this release.*
No changelog for this release.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.19...6.9.20
[backend/client] add ruleApplyAsync method (#11626) by @JeremyCloarec in https://github.com/OpenCTI-Platform/opencti/pull/14034
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.18...6.9.19
*No changelog for this release.*
No changelog for this release.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.17...6.9.18
*No changelog for this release.*
No changelog for this release.
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.16...6.9.17
[doc] openaev : correct link to openaev documentation by @MarineLeM in https://github.com/OpenCTI-Platform/opencti/pull/14118
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.15...6.9.16
[backend] Delete workbenches as other files when deleting an entity (#14301) by @SamuelHassine in https://github.com/OpenCTI-Platform/opencti/pull/143
Full Changelog: https://github.com/OpenCTI-Platform/opencti/compare/6.9.14...6.9.15
Your coding agent can read these notes before it upgrades. Set up the MCP server →