PT-2026-79345 · Misp-Stix · Misp-Stix
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
misp-stix (affected versions not specified)
Description
A flaw in the STIX import logic allows a crafted STIX document to influence security-sensitive MISP attribute metadata. The system automatically selects between an internal MISP parser and an external STIX parser based on metadata within the document, such as tool labels for STIX2 or the document title for STIX1. Since these indicators are controlled by the producer, an attacker can spoof them to force the use of the internal parser. When STIX2 content is processed as an internal MISP export, the
x misp attributes dictionary is passed directly to the misp object.add attribute() function without restriction. This allows an attacker to inject unauthorized fields such as distribution, sharing group id, and tags. Such manipulation can lead to information being shared against organizational policy or the disruption of downstream automation. This issue involves mass assignment, where externally influenced fields are accepted without an allow-list, and the use of untrusted values for security-relevant classification decisions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp-Stix