Git · Cti-Transmute · CVE-2026-9806
**Name of the Vulnerable Software and Affected Versions**
CTI Transmute (affected versions not specified)
**Description**
A stored cross-site scripting (XSS) issue exists in the notification panel. Notification messages containing user-controlled convert names were rendered in the notification bell dropdown using `innerHTML` without adequate sanitization. An attacker who can influence a convert name included in a notification can inject arbitrary JavaScript. This script executes in the browser of an authenticated user upon opening the notification panel, potentially allowing the attacker to perform actions in the victim's session or access application information. This issue was limited to a development branch.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.