PT-2026-68816 · Unknown · Cti-Transmute
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
CTI-Transmute (affected versions not specified)
Description
Stored cross-site scripting occurs due to insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can inject malicious Vue expressions using
[[ ... ]] delimiters within a public conversion's name, description, or user profile names. While Jinja HTML escaping is used, the data is placed in a DOM region compiled by Vue, which interprets the input as a template expression instead of plain text. By utilizing the JavaScript Function constructor via [].constructor.constructor(...), an attacker can execute arbitrary JavaScript in the security context of the CTI-Transmute origin. This bypasses the nonce-based Content Security Policy because the Vue runtime compiler requires the unsafe-eval policy exception. The payload is stored and executes when a user or administrator views the affected page, potentially allowing the attacker to access sensitive data, extract API keys or tokens, perform authenticated actions, or modify application data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cti-Transmute