What is CVE-2026-73156?
CVE-2026-73156 arises from a failure to HTML-escape attacker-controlled values in ECharts Sunburst and Treemap tooltips in affected versions of cti-transmute. This could allow malicious STIX/MISP data to be executed in the browser. Users should follow official patches and updates for the package.
Azərbaycanca: CVE-2026-73156 zəifliyi cti-transmute paketinin təsirlənmiş versiyalarında ECharts Sunburst və Treemap alətləri üçün HTML-dən qaçışın düzgün tətbiq edilməməsindən qaynaqlanır. Bu, STIX/MISP məlumatlarındakı zərərli dəyərlərin brauzerdə işlənməsinə səbəb ola bilər. İstifadəçilər paketin yenilənməsini tövsiyə edən rəsmi düzəlişləri izləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
In which components does CVE-2026-73156 involve improper HTML escaping?
The vulnerability involves improper HTML escaping in ECharts Sunburst and Treemap tooltips within the cti-transmute package.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.