CVE-2026-103321
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Summary
MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.
The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.
Preconditions:
An authenticated MISP user with the ability to create or modify an event graph entry.
A second user (the victim) who views the event graph and triggers the preview popover.
Impact:
Execution of arbitrary JavaScript in the victim's browser within the MISP application context.
Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser.
Potential for performing actions on behalf of the victim within the MISP application.
Affected: MISP versions prior to the fix (commit applied after v2.5.48).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MISP | MISP | 0 < 2.5.48 | affected |
Weaknesses
- CWE-79: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-20: CWE-20 Improper Input Validation
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.