“OpenKM Critical Vulnerabilities”
Terra System Labs has recently published a high-level security advisory regarding critical vulnerabilities in OpenKM, including:
- Local File Inclusion (LFI)
- Unrestricted SQL command execution
- Remote Code Execution (RCE).
These issues were identified through controlled security research and responsibly disclosed earlier. The current publication intentionally does not include exploit paths or payloads.
🔗 High-level advisory:
https://terrasystemlabs.com/post?slug=openkm-zero-day-vulnerabilities-critical-disclosure
A detailed technical disclosure, including defensive validation artifacts (PoC), is planned for Friday, 16 January 2026, following responsible disclosure timelines.
This notice is shared to help users and maintainers assess risk and take appropriate mitigation steps.
- Terra System Labs Security Research Team
