PT-2026-79352 · Misp-Stix · Misp-Stix

·

CVE-2026-77751

·

Published

2026-08-21

·

Updated

2026-08-25

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions misp-stix (affected versions not specified)
Description A path traversal issue exists in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export. The system constructs a filesystem path by joining the configured MISP object-template directory, the object name, and definition.json. Because object names from untrusted STIX or MISP content are not sufficiently restricted, an attacker can provide a crafted name containing path separators or traversal sequences like ../ to escape the intended directory and load a definition.json file from another accessible location. During STIX 2 import, the x misp name variable from a custom STIX object can trigger this mechanism. This issue can be persistent, as a malicious name stored in a MISP event may be processed during STIX 2 export by a process with higher privileges. If a suitable file is found outside the template directory, its contents may be interpreted as a template, leading to the disclosure of local data and the modification of the object's metadata or semantics.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77751

Affected Products

Misp-Stix