CVE-2026-73157: cti-transmute Remote MISP Event Browser Allows Cross-Site Scripting via Malicious Event Metadata
Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, organization names, tags, tag colors, TLP labels, distribution labels, and error/flash text may be controlled by the remote MISP server, a malicious or compromised remote instance could return crafted values that inject HTML or script-capable content into the cti-transmute interface.
The patch explicitly notes that remote-derived values must not reach innerHTML, and replaces string-built rows and badges with DOM nodes populated through textContent. It also restricts remote-controlled tag colors to six-digit hexadecimal values, preventing malicious CSS values such as url(...).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73157?
CVE-2026-73157 has a risk score of 52, indicating a moderate severity level.
What kind of vulnerability is CVE-2026-73157?
CVE-2026-73157 is a Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2026-73157?
To fix CVE-2026-73157, update to the latest version of cti-transmute that addresses this vulnerability.
What impact does CVE-2026-73157 have on users?
CVE-2026-73157 allows attackers to execute malicious scripts in the context of the user's browser, potentially compromising their data.
Which versions of cti-transmute are affected by CVE-2026-73157?
CVE-2026-73157 affects all versions of cti-transmute prior to the fix for this vulnerability.