PT-2026-70082 · Unknown · Cti-Transmute

·

CVE-2026-73156

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions cti-transmute (affected versions not specified)
Description The software fails to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names, which may originate from STIX or MISP data—including STIX types, relationship type, pattern prefixes, and MISP category or type values—are processed without proper sanitization. Because ECharts interprets the formatter return value as HTML, an attacker can inject markup or script-capable content. This allows for the execution of malicious content when a user hovers over the affected slice in the visualization.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73156

Affected Products

Cti-Transmute