Git · Bsimvis · CVE-2026-53693
**Name of the Vulnerable Software and Affected Versions**
MISP BSimVis versions prior to 0.2.1
**Description**
A stored cross-site scripting issue exists in the tag rendering code. Several client-side rendering paths interpolate tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline JavaScript event handlers, and CSS style values without context-appropriate escaping. An attacker capable of creating or influencing stored tag or metadata values can inject a crafted payload. When a victim views affected BSimVis pages, the payload executes arbitrary JavaScript in their session, potentially allowing the attacker to perform actions as the victim, read available data, or alter application content.
**Recommendations**
Update to version 0.2.1 or later.