CVE-2026-73159: cti-transmute Stored XSS via Crafted Tag Icon on Admin Triage Interface
Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() previously constructed an HTML string directly from the icon value:
<i class="fas fa-${name}"></i>
Because the icon is user-supplied, a crafted value could break out of the intended markup and inject attacker-controlled HTML. When the affected tag was later rendered, including on the administrative triage interface, the payload could execute in the viewer's browser.
The patch mitigates the issue at multiple layers: v-html is replaced with Vue :class binding, mapIcon() now returns only a constrained FontAwesome class string, and the backend validates icons against the FontAwesome catalogue or a strict [a-z0-9-]{1,40} slug pattern before storing them.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update the tag icon rendering to stop using Vue's v-html with the user-supplied icon value and instead use a Vue :class binding so the icon cannot inject HTML.
cti-transmute (frontend Vue) Use v-html for icon rendering = Replace with Vue :class binding - Configuration
Modify helper mapIcon() so it no longer constructs an HTML string from the icon value; instead it must return only a constrained FontAwesome class string.
cti-transmute (frontend) mapIcon() output construction = Return constrained FontAwesome class string only - Configuration
On the backend, validate the user-supplied icon against the FontAwesome catalogue OR a strict icon slug pattern [a-z0-9-]{1,40} before storing it.
cti-transmute (backend) Icon validation before storing = Validate against FontAwesome catalogue or strict [a-z0-9-]{1,40} slug pattern - Compensating control
Apply the above fixes across both the viewer and the administrative triage interface to prevent stored XSS from executing in the administrator's browser.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73159?
CVE-2026-73159 has a risk rating of 40.
How do I fix CVE-2026-73159?
To resolve CVE-2026-73159, avoid using user-supplied values directly in HTML and ensure proper input validation and sanitization.
What type of vulnerability is CVE-2026-73159?
CVE-2026-73159 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Which versions of cti-transmute are affected by CVE-2026-73159?
Affected versions are those that allow user-supplied icon values to be rendered without proper sanitization.
What impact does CVE-2026-73159 have?
CVE-2026-73159 can allow an attacker to execute arbitrary JavaScript in the context of the user’s browser.