Description
MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.

Preconditions:

- A linked/remote MISP server is configured and connected to the local instance.

- The linked server supplies a crafted tag ID in an event.

- An authenticated user views the event preview and interacts with the affected tag element.

Impact:

- Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.

Affected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).
Published: 2026-10-02
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting with arbitrary script execution
Action: Apply Patch
AI Analysis

Impact

MISP contains an XSS vulnerability in the event preview page that renders tag identifiers within an inline JavaScript onclick attribute. The tag ID is HTML‑escaped but not sanitized for the JavaScript string context, so a malicious linked MISP server can supply a tag ID containing characters such as a single quote to break out of the JavaScript string literal and inject arbitrary scripting code. When an authenticated user clicks on the affected tag, the injected script runs in the context of the user's browser session, potentially allowing session hijacking, data exfiltration, or execution of unintended actions on the user's behalf.

Affected Systems

The vulnerability affects installations of MISP prior to the fix commit that casts the remote tag ID to an integer. Versions older than v2.5.48 are considered vulnerable, though the exact boundary is unconfirmed. Any system configured with one or more linked/remote MISP servers that uses the event preview feature is in scope.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available, so the exploitation probability is unclear. The vulnerability is not listed in CISA's KEV catalog. An attacker must control a linked remote server, supply a crafted tag ID, and the victim must have authenticated access to the event preview and click the affected tag. The exploit happens locally in the user's browser, so it requires user interaction rather than remote code execution, limiting the attack surface but still posing a significant risk to the affected user.

Generated by OpenCVE AI on October 2, 2026 at 17:39 UTC.

Remediation

Vendor Solution

The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.


OpenCVE Recommended Actions

  • Update MISP to the latest release that incorporates commit 70ad174dd, which casts the remote tag ID to an integer before embedding it in the JavaScript handler.
  • If a quick patch is not possible, disable or remove linked remote MISP server connections that provide event preview data until the vulnerability is fixed.
  • Monitor event preview interactions for signs of cross‑site scripting activity and review user session logs for anomalous behavior.

Generated by OpenCVE AI on October 2, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script. Preconditions: - A linked/remote MISP server is configured and connected to the local instance. - The linked server supplies a crafted tag ID in an event. - An authenticated user views the event preview and interacts with the affected tag element. Impact: - Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user. Affected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).
Title MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler
First Time appeared Misp
Misp misp
Weaknesses CWE-116
CWE-79
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-02T16:18:12.403Z

Reserved: 2026-10-02T15:51:32.541Z

Link: CVE-2026-104907

cve-icon Vulnrichment

Updated: 2026-10-02T16:18:07.391Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:48.253

Modified: 2026-10-02T17:17:04.823

Link: CVE-2026-104907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:45:17Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')