PT-2026-48470 · Git+1 · Bsimvis

·

CVE-2026-53693

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP BSimVis versions prior to 0.2.1
Description A stored cross-site scripting issue exists in the tag rendering code. Several client-side rendering paths interpolate tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline JavaScript event handlers, and CSS style values without context-appropriate escaping. An attacker capable of creating or influencing stored tag or metadata values can inject a crafted payload. When a victim views affected BSimVis pages, the payload executes arbitrary JavaScript in their session, potentially allowing the attacker to perform actions as the victim, read available data, or alter application content.
Recommendations Update to version 0.2.1 or later.

Exploit

Fix

XSS

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53693

Affected Products

Bsimvis