๐Ÿ” CVE Alert

CVE-2026-103321

UNKNOWN 0.0

MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script. Preconditions: - An authenticated MISP user with the ability to create or modify an event graph entry. - A second user (the victim) who views the event graph and triggers the preview popover. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser. - Potential for performing actions on behalf of the victim within the MISP application. Affected: MISP versions prior to the fix (commit applied after v2.5.48).

CWE CWE-79 CWE-20
Vendor misp
Product misp
Published Sep 30, 2026
Last Updated Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for misp misp

Be the first to know when new unknown vulnerabilities affecting misp misp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MISP / MISP
0 < 2.5.48

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MISP/MISP/commit/92c7ccc43

Credits

๐Ÿ” Bastien Bossiroy of NCIA iglocska Claude Opus 4.8