CVE-2026-73159
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-79
Neutralización incorrecta de la entrada durante la generación de la página web (Cross-site Scripting)
Fecha de publicación:
11/08/2026
Última modificación:
11/08/2026
Descripción
*** Pendiente de traducción *** Affected versions of cti-transmute allow a tag&#39;s icon value to be stored and later interpolated into HTML through Vue&#39;s v-html. The helper mapIcon() previously constructed an HTML string directly from the icon value:<br />
<br />
<br />
<br />
<br />
<br />
Because the icon is user-supplied, a crafted value could break out of the intended markup and inject attacker-controlled HTML. When the affected tag was later rendered, including on the administrative triage interface, the payload could execute in the viewer&#39;s browser.<br />
<br />
<br />
The patch mitigates the issue at multiple layers: v-html is replaced with Vue :class binding, mapIcon() now returns only a constrained FontAwesome class string, and the backend validates icons against the FontAwesome catalogue or a strict [a-z0-9-]{1,40} slug pattern before storing them.
Impacto
Puntuación base 4.0
5.10
Gravedad 4.0
MEDIA



