๐Ÿ” CVE Alert

CVE-2026-104906

UNKNOWN 0.0

MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim's MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim's MISP session. Preconditions: - The victim must be an authenticated MISP user with access to the TAXII object viewer. - The victim must open or view the crafted TAXII object. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface. - Potential for performing actions on behalf of the authenticated user. Affected versions: <2.5.48.

CWE CWE-79
Vendor misp
Product misp
Published Oct 2, 2026
Last Updated Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for misp misp

Be the first to know when new unknown vulnerabilities affecting misp misp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MISP / MISP
0 < 2.5.48

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MISP/MISP/commit/1bed4ca0c

Credits

๐Ÿ” Jeroen Pinoy iglocska Claude Opus 5.5 (1M context)