A vulnerability was found in MISP cti-transmute up to 1.4.0. It has been classified as problematic. This issue affects some unknown processing of the component Pivotick. Performing a manipulation of the argument svgIcon results in cross site scripting.

This vulnerability is cataloged as CVE-2026-73158. It is possible to initiate the attack remotely. There is no exploit available.

Applying a patch is the recommended action to fix this issue.