<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cti-Transmute (1.4.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/cti-transmute-1.4.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 04 Aug 2026 19:43:37 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/cti-transmute-1.4.0/feed.xml" rel="self" type="application/rss+xml"/><item><title>Vulnerabilities in MISP cti-transmute</title><link>https://feed.craftedsignal.io/briefs/2026-08-misp-cti-transmute-vulns/</link><pubDate>Tue, 04 Aug 2026 19:43:37 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-misp-cti-transmute-vulns/</guid><description>The MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.</description><content:encoded><![CDATA[<p>The MISP project has issued a security advisory for the cti-transmute utility affecting all versions up to and including 1.4.0. The updates address several security weaknesses identified in the tool's handling of web requests and administrative actions. Specifically, the patches block unauthorized file and network fetches triggered during PDF evaluation, enforce stricter limits on activity-timeline day ranges to mitigate resource exhaustion, and mandate HTTP POST methods for user deletion to prevent unauthorized administrative actions via cross-site request forgery (CSRF) or simple GET requests. Users are advised to upgrade to the latest version to prevent potential exploitation of these flaws.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could lead to unauthorized access to sensitive files, unintended network connections originating from the application server, and unauthorized administrative actions such as the deletion of application users. Organizations utilizing cti-transmute for threat intelligence processing or reporting workflows are potentially at risk if the application is accessible to untrusted users or processes malicious input.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update cti-transmute to the latest available version beyond 1.4.0 to ensure all security patches are applied.</li>
<li>Audit web server and application logs for unusual GET requests to endpoints associated with user management, as these may indicate attempts to leverage the user deletion flaw.</li>
<li>Review network egress logs for unexpected connections originating from the host running cti-transmute, which may indicate exploited file or network fetch vulnerabilities.</li>
<li>Implement strict access controls for the cti-transmute interface to ensure only authorized personnel can trigger evaluation functions.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>cti-transmute</category><category>misp</category><category>patch-management</category></item></channel></rss>