Description
MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement.

An attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim.

Preconditions:

- The victim must be authenticated to MISP and access the analyst data view for an attribute or object.

- The attacker must supply a malicious seed value in the URL path.

Impact:

- Execution of arbitrary JavaScript in the victim's browser session.

- Potential theft of session credentials or sensitive data visible in the page.

- Manipulation of the analyst data interface.

Affected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).
Published: 2026-10-01
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting enabling arbitrary JavaScript execution in the user’s browser
Action: Apply Patch
AI Analysis

Impact

A reflected XSS flaw exists in MISP’s analyst data notes panel: the seed path parameter supplied in the URL is injected directly into inline JavaScript without sanitization or type validation. When an authenticated user opens a maliciously crafted link, the embedded script runs in the victim’s browser context, allowing an attacker to read session information, capture sensitive data displayed on the page, or perform actions as the user. The vulnerability is a classic example of CWE‑79 – Cross‑Site Scripting.

Affected Systems

MISP installations running versions prior to the fix revision 58925dbf0, which corresponds to releases before v2.5.48, are vulnerable. The issue is tied to the MISP product.

Risk and Exploitability

The CVSS score of 4.8 places the issue in the medium‑risk range, and there is no EPSS data available, meaning the current exploit probability is unknown. The vulnerability is not listed in CISA’s KEV catalog, but it can be triggered via a simple phishing link that convinces an authenticated user to visit a crafted URL. Once the victim opens the link, the exploit is executed immediately within the browser, providing the attacker with the ability to harvest session tokens or inject malicious content.

Generated by OpenCVE AI on October 1, 2026 at 11:58 UTC.

Remediation

Vendor Solution

The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.


OpenCVE Recommended Actions

  • Upgrade MISP to a version that includes the fix (v2.5.48 or later, or apply commit 58925dbf0).
  • Verify that the seed parameter is validated as an integer in both the controller and view/template layers so that no unsanitized data reaches JavaScript contexts.
  • Review any custom code or plugins that interact with the analyst data notes panel to ensure integer validation is applied, or remove the vulnerable seed parameter from URLs and restrict role-based access to the panel to limit exposure.

Generated by OpenCVE AI on October 1, 2026 at 11:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement. An attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim. Preconditions: - The victim must be authenticated to MISP and access the analyst data view for an attribute or object. - The attacker must supply a malicious seed value in the URL path. Impact: - Execution of arbitrary JavaScript in the victim's browser session. - Potential theft of session credentials or sensitive data visible in the page. - Manipulation of the analyst data interface. Affected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).
Title MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter
First Time appeared Misp
Misp misp
Weaknesses CWE-79
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-01T15:06:25.374Z

Reserved: 2026-10-01T08:55:49.992Z

Link: CVE-2026-103664

cve-icon Vulnrichment

Updated: 2026-10-01T15:06:20.671Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:08.713

Modified: 2026-10-01T16:17:38.173

Link: CVE-2026-103664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')