PT-2026-70082 · Unknown · Cti-Transmute
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
cti-transmute (affected versions not specified)
Description
The software fails to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names, which may originate from STIX or MISP data—including STIX types,
relationship type, pattern prefixes, and MISP category or type values—are processed without proper sanitization. Because ECharts interprets the formatter return value as HTML, an attacker can inject markup or script-capable content. This allows for the execution of malicious content when a user hovers over the affected slice in the visualization.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cti-Transmute