{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cti-transmute-1.4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cti-transmute (1.4.0)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","cti-transmute","misp","patch-management"],"_cs_type":"advisory","_cs_vendors":["MISP"],"content_html":"\u003cp\u003eThe MISP project has issued a security advisory for the cti-transmute utility affecting all versions up to and including 1.4.0. The updates address several security weaknesses identified in the tool's handling of web requests and administrative actions. Specifically, the patches block unauthorized file and network fetches triggered during PDF evaluation, enforce stricter limits on activity-timeline day ranges to mitigate resource exhaustion, and mandate HTTP POST methods for user deletion to prevent unauthorized administrative actions via cross-site request forgery (CSRF) or simple GET requests. Users are advised to upgrade to the latest version to prevent potential exploitation of these flaws.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could lead to unauthorized access to sensitive files, unintended network connections originating from the application server, and unauthorized administrative actions such as the deletion of application users. Organizations utilizing cti-transmute for threat intelligence processing or reporting workflows are potentially at risk if the application is accessible to untrusted users or processes malicious input.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate cti-transmute to the latest available version beyond 1.4.0 to ensure all security patches are applied.\u003c/li\u003e\n\u003cli\u003eAudit web server and application logs for unusual GET requests to endpoints associated with user management, as these may indicate attempts to leverage the user deletion flaw.\u003c/li\u003e\n\u003cli\u003eReview network egress logs for unexpected connections originating from the host running cti-transmute, which may indicate exploited file or network fetch vulnerabilities.\u003c/li\u003e\n\u003cli\u003eImplement strict access controls for the cti-transmute interface to ensure only authorized personnel can trigger evaluation functions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T19:43:37Z","date_published":"2026-08-04T19:43:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-misp-cti-transmute-vulns/","summary":"The MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.","title":"Vulnerabilities in MISP cti-transmute","url":"https://feed.craftedsignal.io/briefs/2026-08-misp-cti-transmute-vulns/"}],"language":"en","title":"CraftedSignal Threat Feed - Cti-Transmute (1.4.0)","version":"https://jsonfeed.org/version/1.1"}