{
 "description": "Evidence-bound MITRE ATT&CK techniques observed in ctipilot.ch entries referencing misp-stix cross-document parser state contamination (CVSS 4.0 6.3) \u2014 reused parser instances retained galaxy data, references, titles and timestamps across conversions, so one document's content can appear in the event generated from the next. Last affected 2026.7.8; fixed by commits only.. Score = number of published entries mapping the technique. Pinned dataset: ATT&CK v19.2.",
 "domain": "enterprise-attack",
 "gradient": {
  "colors": [
   "#ffe766",
   "#ff6666"
  ],
  "maxValue": 1,
  "minValue": 0
 },
 "hideDisabled": false,
 "layout": {
  "layout": "side",
  "showID": true,
  "showName": true
 },
 "legendItems": [],
 "metadata": [
  {
   "name": "source",
   "value": "ctipilot.ch"
  },
  {
   "name": "entity",
   "value": "CVE-2026-77761"
  },
  {
   "name": "attack_version",
   "value": "19.2"
  }
 ],
 "name": "misp-stix cross-document parser state contamination (CVSS 4.0 6.3) \u2014 reused parser instances retained galaxy data, references, titles and timestamps across conversions, so one document's content can appear in the event generated from the next. Last affected 2026.7.8; fixed by commits only. \u2014 ctipilot.ch coverage",
 "sorting": 3,
 "techniques": [
  {
   "comment": "entries: 2026-08-23/misp-stix-import-trust-boundary-dos-parser-state",
   "score": 1,
   "techniqueID": "T1499"
  },
  {
   "comment": "entries: 2026-08-23/misp-stix-import-trust-boundary-dos-parser-state",
   "score": 1,
   "techniqueID": "T1565.001"
  },
  {
   "showSubtechniques": true,
   "techniqueID": "T1565"
  }
 ],
 "versions": {
  "attack": "19",
  "layer": "4.5",
  "navigator": "5.1.0"
 }
}