Executive brief
MISP cti-transmute is a tool for converting and managing cybersecurity intelligence data. A flaw in the authorization check for conversion history endpoints allowed users to view the input and output data of deleted conversions that they should not have access to. An attacker able to request history entries could retrieve sensitive information about conversions removed from the system.
Technical details
The vulnerability is an authorization bypass in the conversion-history details endpoint caused by incomplete authorization logic. When a history record references a deleted conversion, the lookup returns None, and the original code only denied access if the conversion object existed and the visibility check failed. This allowed deleted conversions to bypass the authorization check entirely, leaking their retained history input/output data. The fix, committed on July 22, 2026, changes the logic to deny access whenever the conversion is missing or the requester lacks permission, properly closing the bypass.
Affected products
- MISP cti-transmute <commit 88dc65f
Timeline
- 2026-08-10: disclosed
- 2026-07-22: patched: commit 88dc65f