Misp · Misp · CVE-2026-103662
**Name of the Vulnerable Software and Affected Versions**
MISP versions prior to 2.5.48
**Description**
Reflected cross-site scripting (XSS) exists in the legacy taxonomy tag management confirmation forms used for adding and disabling tags. The issue occurs because the application echoes a user-supplied tag name value from the request unescaped into the rendered HTML output. An authenticated site administrator who visits a crafted URL can have arbitrary JavaScript executed in their browser session, potentially leading to the theft of session tokens, CSRF tokens, or the performance of privileged actions within the interface.
**Recommendations**
Update to version 2.5.48 or later.
As a temporary mitigation, disable the legacy taxonomy tag confirmation views.