๐Ÿ” CVE Alert

CVE-2026-103389

UNKNOWN 0.0

MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method. A user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session. Impact: - Arbitrary script execution in the context of the victim's MISP session - Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim - Affects both the default and Overmind UI themes Affected versions: <2.5.48

CWE CWE-79 CWE-20
Vendor misp
Product misp
Published Sep 30, 2026
Last Updated Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for misp misp

Be the first to know when new unknown vulnerabilities affecting misp misp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MISP / MISP
0 < 2.5.48

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MISP/MISP/commit/8ea5783dd

Credits

๐Ÿ” Jeroen Pinoy iglocska Claude Fable 5.1