Impact
The vulnerability arises when user‑supplied graph configuration data is insufficiently validated. The svgIcon style property is interpreted as HTML by Pivotick, allowing a malicious user to embed JavaScript that runs in the browser of any viewer who loads the configuration. This stored XSS can lead to script execution, credential theft, or other client‑side attacks.
Affected Systems
Vulnerable software is MISP cti‑transmute. No specific product versions are listed in the advisory, so all current releases that store graph configurations are potentially affected until a schema fix is applied.
Risk and Exploitability
The CVSS score is 5.1, indicating moderate severity. EPSS data is not available, and the flaw is not in the CISA KEV catalog. Attackers can exploit the issue by submitting a crafted configuration as an authenticated user; the malicious payload will then execute in the browsers of other users, including administrators, who view the configuration. Because it is a stored XSS, it does not require network interaction after the configuration is saved.
OpenCVE Enrichment