PT-2026-68816 · Unknown · Cti-Transmute

·

CVE-2026-71502

·

Published

2026-08-06

·

Updated

2026-08-09

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions CTI-Transmute (affected versions not specified)
Description Stored cross-site scripting occurs due to insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can inject malicious Vue expressions using [[ ... ]] delimiters within a public conversion's name, description, or user profile names. While Jinja HTML escaping is used, the data is placed in a DOM region compiled by Vue, which interprets the input as a template expression instead of plain text. By utilizing the JavaScript Function constructor via [].constructor.constructor(...), an attacker can execute arbitrary JavaScript in the security context of the CTI-Transmute origin. This bypasses the nonce-based Content Security Policy because the Vue runtime compiler requires the unsafe-eval policy exception. The payload is stored and executes when a user or administrator views the affected page, potentially allowing the attacker to access sensitive data, extract API keys or tokens, perform authenticated actions, or modify application data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71502

Affected Products

Cti-Transmute