A vulnerability was found in MISP cti-transmute up to 1.4.0. It has been declared as problematic. Impacted is the function mapIcon of the component Icon. Executing a manipulation of the argument icon can lead to injection.

This vulnerability is registered as CVE-2026-73159. It is possible to launch the attack remotely. No exploit is available.

It is best practice to apply a patch to resolve this issue.