Yeti Platform is a focused threat-intelligence and malware-analysis platform where the observed vulnerability footprint has been narrow and concentrated in its core product. This compact vendor profile reflects a specialized rather than a broadly distributed asset; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yeti Platform over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-46507HIGH A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application | May 8, 2026 | 7.3 | 41 | NO | YES |
CVE-2024-46508HIGH yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET). | May 8, 2026 | 7.5 | 28 | NO | NO |
CVE-2024-45412HIGH Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Remote user-controlled data tags can reach a Unicode normalizat | Sep 10, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yeti Platform.
Media articles that mention a CVE ID that affects a product developed by Yeti Platform — matched by CVE ID, not by vendor name.