Insufficient Validation Vulnerability in cti-transmute Affecting MISP
CVE-2026-73158

5.1MEDIUM

Key Information:

Vendor

Misp

Vendor
CVE Published:
11 August 2026

What is CVE-2026-73158?

The cti-transmute component of MISP is vulnerable due to inadequate validation of saved graph configuration data. This issue allows a malicious user to inject a crafted 'svgIcon' value that is rendered as HTML in other users' browsers, leading to potential script execution vulnerabilities. The implications are especially concerning since user-created configurations can be displayed to others, including administrators. To mitigate the risk, a fix has been implemented that enforces strict validation rules on both server and client sides. This involves limiting accepted properties and sanitizing existing configurations, thereby preventing the exploitation of this vulnerability.

Affected Version(s)

cti-transmute 0 <= 1.4.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Christian Studer
.