PT-2026-85076 · Misp · Misp
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
A persistent unsafe URL injection exists in the ButtonWidget configuration of the dashboard. The issue occurs because dashboard widget URLs were validated only during rendering and not when the configuration was saved. This allows an authenticated user with permissions to modify dashboard settings to persist arbitrary URL values, including those using the
javascript: scheme. If these values reach a rendering or navigation path that lacks runtime validation, it could lead to client-side script execution within the security context of the MISP session. This could enable an attacker to perform actions using the privileges of the affected user or access session-specific information. This flaw is characterized as a persistence-layer validation gap and a defense-in-depth weakness.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Misp