Junglewise Threat Intelligence

CVE-2026-73156: MISP cti-transmute XSS in ECharts tooltip formatters

CVE-2026-73156 · Severity: info · Published 2026-08-11

Vendors: Misp.

Executive brief

cti-transmute is a tool used to convert threat intelligence data (STIX and MISP formats) into visualizations. The vulnerability allows an attacker to inject malicious HTML and JavaScript code into interactive tooltips displayed when users hover over chart elements. If an attacker can introduce crafted malicious data into a conversion, other users viewing the resulting visualization could have arbitrary code executed in their browser.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in the ECharts Sunburst and Treemap tooltip formatters. Slice names are sourced directly from converted STIX or MISP data (including types, relationships, patterns, and categories) and interpolated into tooltip formatter strings without HTML-escaping. Since ECharts interprets the formatter return value as HTML, an attacker controlling the input data can inject arbitrary markup and script-capable content. The attack requires the attacker to supply malicious conversion data, which is then executed when another user hovers over the visualization. The patch implements HTML-escaping via escapeHtml() on the interpolated values (p.name, p.data.value, p.value).

Affected products

  • MISP cti-transmute

Timeline

  • 2026-08-11: disclosed

References