CVE-2026-103321 Details
Description
MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script. Preconditions: - An authenticated MISP user with the ability to create or modify an event graph entry. - A second user (the victim) who views the event graph and triggers the preview popover. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser. - Potential for performing actions on behalf of the victim within the MISP application. Affected: MISP versions prior to the fix (commit applied after v2.5.48).
A stored cross-site scripting vulnerability has been identified in MISP within the event graph preview feature. This issue arises because the preview image field accepts and stores data without proper server-side validation. As a result, a crafted value can escape the attribute context and inject arbitrary scripts. The vulnerability affects MISP versions prior to the fix implemented in commit 92c7ccc43, after version 2.5.48.
Users can update to MISP version 2.5.48 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MISP/MISP/commit/92c7ccc43 | CIRCL | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CIRCL |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CIRCL |
Affected Products
| Product | Versions |
|---|---|
| MISP | < 2.5.48 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | CIRCL |
| Sep 30, 2026 | CVE Modified | CISA-ADP |
Volerion