HTML Injection Risk in cti-transmute by MISP
CVE-2026-73157

2.3LOW

Key Information:

Vendor

Misp

Vendor
CVE Published:
11 August 2026

What is CVE-2026-73157?

The cti-transmute tool by MISP is vulnerable to HTML injection due to improper handling of data sourced from a remote MISP instance. The vulnerability arises when event IDs, organization names, and other fields are rendered in the event-browser using HTML interpolation, potentially allowing an attacker to inject malicious HTML or script content. A compromised remote MISP server could exploit this flaw by sending crafted values, undermining the integrity of the interface. A recommended patch has been issued, ensuring that remote-derived values do not reach innerHTML and replacing insecure string-rendered elements with DOM nodes securely populated through textContent.

Affected Version(s)

cti-transmute 0 <= 1.4.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Christian Studer
.