Executive brief
cti-transmute is a tool for converting and managing threat intelligence conversions with private comments and access controls. When users export evaluation reports as Markdown or PDF, the application failed to respect comment-level privacy rules, allowing authorized users to view private comments they should not have access to, along with comment author names. This bypassed access controls that normally restrict comment visibility based on ownership, authorship, and administrative privileges.
Technical details
The vulnerability is an access control bypass in the build_evaluation_report() function, which generates Markdown and PDF exports of evaluation reports. The function failed to apply the same comment visibility rules used during normal API comment retrieval, specifically not calling the can_see_comment() authorization function. An authenticated user with legitimate access to view a conversion could exploit this to export its evaluation report and read all comments including private ones, bypassing the authorization checks that filter by user ownership, comment authorship, privacy settings, and admin status. The fix implements comment filtering using the can_see_comment() function to enforce the same access-control rules during report generation. A patch is available in commit 5dbd19b.
Affected products
- MISP cti-transmute versions prior to commit 5dbd19b39a61eab793586731f1a80d8c38907c42
Timeline
- 2026-07-21: patched: Fix committed in GitHub
- 2026-08-11: disclosed