CVE-2026-73140: cti-transmute Evaluation Report Exports Expose Private Comments and Author Information
Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversion visibility, comment privacy, ownership, authorship, and administrative privileges, buildevaluationreport() previously included all evaluation comments without applying those rules.
Consequently, a user who was authorized to view a conversion could export its evaluation report as Markdown or PDF and obtain private evaluation comments that should only have been visible to the conversion owner, the comment author, or an administrator. The leaked report data also contained the comment author's name. The fix passes the requesting user into the report builder and filters every evaluation comment using the shared access.canseecomment() authorization function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73140?
CVE-2026-73140 has a risk score of 33, indicating a moderate severity vulnerability.
How do I fix CVE-2026-73140?
To fix CVE-2026-73140, update to the latest version of cti-transmute that applies the necessary comment-level access-control rules.
What types of information are exposed in CVE-2026-73140?
CVE-2026-73140 exposes private comments and author information when generating evaluation report exports.
Which versions of cti-transmute are affected by CVE-2026-73140?
All versions of cti-transmute prior to the security update that addresses this issue are affected by CVE-2026-73140.
What impact does CVE-2026-73140 have on data privacy?
CVE-2026-73140 negatively impacts data privacy by failing to restrict access to sensitive comments and author details.