What is CVE-2026-71502?
CVE-2026-71502 is a stored Cross-Site Scripting vulnerability in CTI-Transmute caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conversion with a malicious Vue expression in its name or description. Users should update CTI-Transmute to the latest patched version and avoid interacting with untrusted conversions.
Azərbaycanca: CVE-2026-71502 CTI-Transmute proqramında saxlanılan XSS zəifliyidir, server tərəfindən işlənən istifadəçi məlumatlarında Vue template ifadə ayırıcılarının yetərsiz neytrallaşdırılması nəticəsində yaranır. Doğrulanmamış hücumçu açıq konversiya yaradaraq onun adı və ya təsviri vasitəsilə zərərli Vue ifadəsi yeridə bilər. İstifadəçilər CTI-Transmute tətbiqini ən son versiyaya yeniləməli və şübhəli konversiyalardan yayınmalıdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
How can an attacker exploit the CVE-2026-71502 vulnerability to compromise a system?
An unauthenticated attacker can create a public conversion with a malicious Vue expression in its name or description.
What should CTI-Transmute users do to protect themselves against CVE-2026-71502?
Users should update CTI-Transmute to the latest patched version and avoid interacting with untrusted conversions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.