CVE-2026-73157: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in MISP cti-transmute
Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, organization names, tags, tag colors, TLP labels, distribution labels, and error/flash text may be controlled by the remote MISP server, a malicious or compromised remote instance could return crafted values that inject HTML or script-capable content into the cti-transmute interface. The patch explicitly notes that remote-derived values must not reach innerHTML, and replaces string-built rows and badges with DOM nodes populated through textContent. It also restricts remote-controlled tag colors to six-digit hexadecimal values, preventing malicious CSS values such as url(...).
AI Analysis
Technical Summary
This vulnerability in MISP cti-transmute (<=1.4.0) involves improper neutralization of input (CWE-79 and CWE-116) when rendering data obtained from remote MISP instances. The affected interface uses HTML interpolation to display fields like event IDs, organization names, tags, and labels, which can be controlled by the remote server. A malicious or compromised remote MISP instance can craft values that inject HTML or script-capable content, leading to cross-site scripting. The patch notes indicate that safe DOM methods like textContent replace string-built HTML, and tag colors are restricted to six-digit hex values to prevent malicious CSS injection. No official patch or remediation level is stated in the advisory.
Potential Impact
An attacker controlling a remote MISP instance can inject malicious HTML or scripts into the cti-transmute event-browser interface of a client using affected versions, potentially leading to cross-site scripting attacks. This could allow execution of arbitrary scripts in the context of the affected user's browser session. However, the CVSS score of 2.3 and the low severity rating indicate limited impact, possibly due to required user interaction and partial vector complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor notes that safe coding practices such as avoiding innerHTML and using textContent for DOM population, as well as restricting tag color inputs, are part of the fix. Users should monitor the official MISP project for updates or patches addressing this vulnerability and avoid using untrusted remote MISP instances until a fix is applied.
CVE-2026-73157: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in MISP cti-transmute
Description
Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, organization names, tags, tag colors, TLP labels, distribution labels, and error/flash text may be controlled by the remote MISP server, a malicious or compromised remote instance could return crafted values that inject HTML or script-capable content into the cti-transmute interface. The patch explicitly notes that remote-derived values must not reach innerHTML, and replaces string-built rows and badges with DOM nodes populated through textContent. It also restricts remote-controlled tag colors to six-digit hexadecimal values, preventing malicious CSS values such as url(...).
CVSS v4.0
Score 2.3low
Affected software
MISP
cti-transmute
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in MISP cti-transmute (<=1.4.0) involves improper neutralization of input (CWE-79 and CWE-116) when rendering data obtained from remote MISP instances. The affected interface uses HTML interpolation to display fields like event IDs, organization names, tags, and labels, which can be controlled by the remote server. A malicious or compromised remote MISP instance can craft values that inject HTML or script-capable content, leading to cross-site scripting. The patch notes indicate that safe DOM methods like textContent replace string-built HTML, and tag colors are restricted to six-digit hex values to prevent malicious CSS injection. No official patch or remediation level is stated in the advisory.
Potential Impact
An attacker controlling a remote MISP instance can inject malicious HTML or scripts into the cti-transmute event-browser interface of a client using affected versions, potentially leading to cross-site scripting attacks. This could allow execution of arbitrary scripts in the context of the affected user's browser session. However, the CVSS score of 2.3 and the low severity rating indicate limited impact, possibly due to required user interaction and partial vector complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor notes that safe coding practices such as avoiding innerHTML and using textContent for DOM population, as well as restricting tag color inputs, are part of the fix. Users should monitor the official MISP project for updates or patches addressing this vulnerability and avoid using untrusted remote MISP instances until a fix is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CIRCL
- Date Reserved
- 2026-08-11T08:06:56.023Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7adcc4bf8831d539683753
Added to database: 08/11/2026, 08:26:44 UTC
Last enriched: 08/11/2026, 08:46:33 UTC
Last updated: 09/25/2026, 01:47:44 UTC
Views: 50
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.