PT-2026-103126 · Misp · Misp
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.48
Description
A stored cross-site script (XSS) issue exists in the event graph preview feature. The application accepts and stores the event graph preview image field without server-side validation. On the client side, this value is rendered into the
src attribute of an HTML img element using string concatenation, which allows a crafted value to escape the attribute context and execute arbitrary JavaScript in the victim's browser. This requires an authenticated user with permissions to create or modify event graph entries and a second user who views the graph and triggers the preview popover. This can lead to the theft of session tokens, cookies, or sensitive data, and allow actions to be performed on behalf of the victim.Recommendations
Update to version 2.5.48 or later.
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Misp