Junglewise Threat Intelligence

CVE-2026-73161: MISP cti-transmute cross-site scripting in search highlighting

CVE-2026-73161 · Severity: info · Published 2026-08-11

Vendors: Misp.

Executive brief

cti-transmute is a web application used to convert and display cyber threat intelligence (CTI) data. A flaw in the search highlighting feature fails to escape user-controlled data before rendering it as HTML, allowing malicious markup in the conversion table to be interpreted as executable code in the browser rather than displayed as text.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in the highlight() function of the search highlighting feature. The root cause is improper handling of conversion-table values: the function performed regex replacement and inserted <mark> tags without escaping special HTML characters such as <, >, &, and quotes in the original content. Because the output is used by an HTML-rendering sink, an attacker can embed malicious markup in conversion table data that will be interpreted as HTML. The fix introduces a highlightMatches() helper that first converts special characters into HTML entities before inserting the <mark> element. Network access to the web application is required; no authentication or user interaction beyond viewing the page is needed.

Affected products

  • MISP cti-transmute versions prior to commit ac495641ef3ca927676a73ba8f1bcdfd952413df

Timeline

  • 2026-08-11: disclosed

References