Description
MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim's MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim's MISP session.

Preconditions:

- The victim must be an authenticated MISP user with access to the TAXII object viewer.

- The victim must open or view the crafted TAXII object.

Impact:

- Execution of arbitrary JavaScript in the victim's browser within the MISP application context.

- Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface.

- Potential for performing actions on behalf of the authenticated user.

Affected versions: <2.5.48.
Published: 2026-10-02
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Stored XSS leading to arbitrary JavaScript execution in the victim’s browser
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw in the TAXII object viewer. When a victim opens a malicious TAXII object, the server renders unescaped JSON string properties inside an HTML pre block, allowing an attacker to inject and execute arbitrary JavaScript in the context of the victim’s MISP session. This can lead to theft of session cookies, API keys, or other sensitive data and enable the attacker to perform actions as the authenticated user.

Affected Systems

The flaw affects MISP releases prior to 2.5.48. Users running MISP versions earlier than 2.5.48 are susceptible, regardless of their operating system, as the issue originates in the web application itself.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no current mass exploitation. However, the attack requires a crafted TAXII object and an authenticated MISP user who views the object, making it a targeted, web‑based exploit that can be executed with any gallery or subscription mechanism that the MISP instance uses to ingest remote TAXII objects.

Generated by OpenCVE AI on October 2, 2026 at 17:39 UTC.

Remediation

Vendor Solution

The fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector.


OpenCVE Recommended Actions

  • Upgrade MISP to version 2.5.48 or later, which applies HTML encoding to the JSON string before displaying it in the pre element.
  • Limit the TAXII servers your MISP instance subscribes to, allowing only trusted and verified sources to supply objects.
  • If unable to upgrade immediately, disable or remove the TAXII object viewer from exposed pages to prevent rendering of potentially malicious content.

Generated by OpenCVE AI on October 2, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim's MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim's MISP session. Preconditions: - The victim must be an authenticated MISP user with access to the TAXII object viewer. - The victim must open or view the crafted TAXII object. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface. - Potential for performing actions on behalf of the authenticated user. Affected versions: <2.5.48.
Title MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output
First Time appeared Misp
Misp misp
Weaknesses CWE-79
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 6.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-02T16:17:21.730Z

Reserved: 2026-10-02T15:49:31.457Z

Link: CVE-2026-104906

cve-icon Vulnrichment

Updated: 2026-10-02T16:17:15.910Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:48.010

Modified: 2026-10-02T17:17:04.633

Link: CVE-2026-104906

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')