Misp · Misp · CVE-2026-103321
**Name of the Vulnerable Software and Affected Versions**
MISP versions prior to 2.5.48
**Description**
A stored cross-site script (XSS) issue exists in the event graph preview feature. The application accepts and stores the event graph preview image field without server-side validation. On the client side, this value is rendered into the `src` attribute of an HTML img element using string concatenation, which allows a crafted value to escape the attribute context and execute arbitrary JavaScript in the victim's browser. This requires an authenticated user with permissions to create or modify event graph entries and a second user who views the graph and triggers the preview popover. This can lead to the theft of session tokens, cookies, or sensitive data, and allow actions to be performed on behalf of the victim.
**Recommendations**
Update to version 2.5.48 or later.