Preconditions:
- The victim must be an authenticated MISP user with access to the TAXII object viewer.
- The victim must open or view the crafted TAXII object.
Impact:
- Execution of arbitrary JavaScript in the victim's browser within the MISP application context.
- Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface.
- Potential for performing actions on behalf of the authenticated user.
Affected versions: <2.5.48.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/MISP/MISP/commit/1bed4ca0c |
|
Fri, 02 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim's MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim's MISP session. Preconditions: - The victim must be an authenticated MISP user with access to the TAXII object viewer. - The victim must open or view the crafted TAXII object. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface. - Potential for performing actions on behalf of the authenticated user. Affected versions: <2.5.48. | |
| Title | MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output | |
| First Time appeared |
Misp
Misp misp |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Misp
Misp misp |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CIRCL
Published:
Updated: 2026-10-02T16:17:21.730Z
Reserved: 2026-10-02T15:49:31.457Z
Link: CVE-2026-104906
No data.
Status : Deferred
Published: 2026-10-02T16:16:48.010
Modified: 2026-10-02T16:16:48.123
Link: CVE-2026-104906
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')