Junglewise Threat Intelligence

CVE-2026-73157: MISP cti-transmute stored XSS via remote MISP instance

CVE-2026-73157 · Severity: info · CVSS 0 · Published 2026-08-11

Vendors: Misp.

Executive brief

cti-transmute is a tool that queries and displays threat intelligence data from remote MISP servers in a web interface. When displaying event information from a remote MISP instance, the tool failed to properly sanitize user-controlled fields like event IDs, organization names, and tags. An attacker controlling a remote MISP server could inject malicious HTML or JavaScript code that executes in the browsers of users querying that server, potentially leading to session hijacking, credential theft, or further system compromise.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the event-browser interface where data from remote MISP instances was rendered using HTML interpolation (innerHTML) without sanitization. Affected fields include event IDs, event information, organization names, tags, tag colors, TLP labels, distribution labels, and error/flash messages—all controlled by the remote MISP server. The attack vector is network-based; a malicious or compromised MISP instance can return crafted payloads that inject script-capable content into the cti-transmute interface without any authentication required from the attacker. The patch (commit 95e6413) mitigates this by replacing string-based HTML construction with DOM nodes populated via textContent and createElement, and by restricting tag colors to valid six-digit hexadecimal values to prevent CSS injection via url(...) directives.

Affected products

  • MISP cti-transmute versions prior to commit 95e64137358d6fb7f1711523de2bf02ff6b181a7

Timeline

  • 2026-08-11: disclosed: CVE-2026-73157 published
  • 2026-07-27: patched: Fix committed to repository

References