What is CVE-2026-73157?
CVE-2026-73157 is a security vulnerability in cti-transmute where data from a remote MISP instance is rendered into the event-browser interface using HTML interpolation, allowing injection of malicious scripts via fields like event IDs, tags, and error text. Users should update to the latest version immediately.
Azərbaycanca: CVE-2026-73157, cti-transmute alətində uzaq MISP instansiyasından alınan məlumatların event-browser interfeysinə HTML interpolyasiyası ilə ötürülməsi nəticəsində yaranan təhlükəsizlik zəifliyidir. Təcavüzkar, təqdim olunan sahələr vasitəsilə zərərli skript yeridə bilər. İstifadəçilərə məhsulu ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
How can CVE-2026-73157 be exploited in the cti-transmute tool?
The vulnerability arises when data from a remote MISP instance is rendered into the event-browser interface using HTML interpolation, allowing an attacker to inject malicious scripts via submitted fields like event IDs, tags, and error text.
What remediation is recommended for CVE-2026-73157?
Users are recommended to update the cti-transmute product to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.