CVE-2026-73161: cti-transmute Conversion Table Allows XSS via Unescaped Cell Content During Search Highlighting
Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function previously returned the underlying text directly when no search query was supplied, or performed a regex replacement that inserted <mark> tags without first escaping the original content. Because the resulting value is used by an HTML-rendering sink, malicious markup contained in conversion data could be interpreted as HTML rather than displayed as text.
The fix introduces a shared highlightMatches() helper that first converts special characters such as <, >, &, and quotes into HTML entities. Only after escaping does the code insert the application-controlled <mark> element used for search highlighting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73161?
CVE-2026-73161 is categorized with a risk score of 32.
How do I fix CVE-2026-73161?
To fix CVE-2026-73161, ensure that the conversion-table values are properly escaped before being rendered in the highlighting function.
What type of vulnerability is CVE-2026-73161?
CVE-2026-73161 is a Cross-Site Scripting (XSS) vulnerability.
Which versions are affected by CVE-2026-73161?
All versions of cti-transmute that improperly handle conversion-table values during search highlighting are affected by CVE-2026-73161.
What impact does CVE-2026-73161 have on users?
CVE-2026-73161 allows for potential injection of malicious scripts, which could compromise user security through XSS.