Executive brief
cti-transmute is a web application for managing threat intelligence data and comments. A vulnerability allows authenticated users to add or remove emoji reactions on comments they cannot normally view, bypassing visibility controls. This enables users to manipulate comments or infer private information by observing reaction state changes on comments outside their authorized access scope.
Technical details
The react() handler in conversions.py performs insufficient authorization validation. It accepts a user-supplied comment_id and emoji, then directly toggles a reaction via comments_repo.toggle_reaction() after only validating syntax and emoji allowlisting—without verifying the current user can view the target comment. An authenticated attacker who discovers or guesses a comment ID of a private or inaccessible comment can add/remove reactions despite lacking access permissions. The fix retrieves the comment, validates it exists and is not deleted, fetches its associated conversion, and enforces access.can_see_comment(current_user, comment, conversion), rejecting unauthorized attempts with HTTP 403.
Affected products
- MISP cti-transmute versions prior to commit a18c07c
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Fix deployed in commit a18c07c3dd4a74b91ad8dd23d6e84fee4bcbd457