CVE-2026-103662

Summary

MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).

The affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator's browser session.

Preconditions:

  • The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.

  • The victim must be an authenticated site administrator.

  • The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).

Security impact:

  • Execution of arbitrary client-side script in the context of the administrator's browser.

  • Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.

  • Potential for performing privileged actions on behalf of the administrator within the MISP interface.

Affected versions: <2.5.48.

Affected Software

VendorProductVersion RangeStatus
MISPMISP0 < 2.5.48affected

Weaknesses

  • CWE-79: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References