Insufficient Validation Vulnerability in cti-transmute Affecting MISP
CVE-2026-73158
5.1MEDIUM
What is CVE-2026-73158?
The cti-transmute component of MISP is vulnerable due to inadequate validation of saved graph configuration data. This issue allows a malicious user to inject a crafted 'svgIcon' value that is rendered as HTML in other users' browsers, leading to potential script execution vulnerabilities. The implications are especially concerning since user-created configurations can be displayed to others, including administrators. To mitigate the risk, a fix has been implemented that enforces strict validation rules on both server and client sides. This involves limiting accepted properties and sanitizing existing configurations, thereby preventing the exploitation of this vulnerability.
Affected Version(s)
cti-transmute 0 <= 1.4.0
