PT-2026-70086 · Unknown+1 · Cti-Transmute+1

·

CVE-2026-73158

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions cti-transmute (affected versions not specified)
Description Insufficient validation of saved graph configuration data allows a malicious user to store a crafted svgIcon value. Since these configurations can be viewed by other users or administrators, the svgIcon property is interpreted as HTML by Pivotick, leading to script execution in the viewer's browser.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73158

Affected Products

Pivotick
Cti-Transmute