Impact
A flaw in MISP’s background job dispatch mechanism allows an attacker who can submit the events/contact form to inject a reserved CakePHP console switch into the job argument list. The vulnerability originates from job arguments being passed directly as the argv array to the CakePHP console process, where ShellDispatcher::_parsePaths scans the entire argv for path switches such as -app, --app, -working, --working, -root, --root, -webroot, and --webroot. By setting the 'person' field to one of these switches and the 'message' field to a phar:// URI pointing to a malicious archive, the attacker causes the CakePHP bootstrap to load Config/core.php from that archive and execute attacker‑controlled PHP code with the privileges of the MISP web user. This provides full remote code execution on the host, enabling data exfiltration, persistence, and lateral movement. The exploit is deterministic once the crafted parameters are accepted; no special timing or race condition is required and the attack can be performed by anyone able to submit the events/contact endpoint.
Affected Systems
The issue impacts the open‑source MISP platform; no specific product versions are listed in the CNA data, so any deployment that has not applied the referenced patch (commit 120813344) remains vulnerable.
Risk and Exploitability
The CVSS score is 8.7, indicating high impact. EPSS is below 1 %, showing very low probability of public exploitation so far, and the vulnerability is not in the CISA KEV catalog. An attacker requires the ability to submit the events/contact endpoint or any other endpoint that forwards user input into background job arguments. No timing or race condition is needed; once the crafted parameters are accepted the exploit is deterministic.
OpenCVE Enrichment