NA at Terra System Labs
Posted 1 month ago
OpenKM Critical Vulnerabilities
Security Advisory Notice - OpenKM Document management System
Terra System Labs has recently published a high-level security advisory regarding critical vulnerabilities in OpenKM, including:
- Local File Inclusion (LFI)
- Unrestricted SQL command execution
- Remote Code Execution (RCE).
These issues were identified through controlled security research and responsibly disclosed earlier. The current publication intentionally does not include exploit paths or payloads.
🔗 High-level advisory:
https://terrasystemlabs.com/post?slug=openkm-zero-day-vulnerabilities-critical-disclosure
A detailed technical disclosure, including defensive validation artifacts (PoC), is planned for Friday, 16 January 2026, following responsible disclosure timelines.
This notice is shared to help users and maintainers assess risk and take appropriate mitigation steps.
- Terra System Labs Security Research Team
What was the project name that you have worked with OpenKM?
Document Management Software
How long have you used OpenKM?
2 Years
How frequently you use OpenKM?
Yearly
How do you find pricing of OpenKM?
inexpensive
What do you like the most about OpenKM?
NA
What do you like the least about OpenKM?
The vendor do not consider security issue as a vulnerability
Rating Breakdown
- Ease of Use
- Features
- Customer Support
- Overall Rating