PT-2026-85076 · Misp · Misp

·

CVE-2026-85230

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description A persistent unsafe URL injection exists in the ButtonWidget configuration of the dashboard. The issue occurs because dashboard widget URLs were validated only during rendering and not when the configuration was saved. This allows an authenticated user with permissions to modify dashboard settings to persist arbitrary URL values, including those using the javascript: scheme. If these values reach a rendering or navigation path that lacks runtime validation, it could lead to client-side script execution within the security context of the MISP session. This could enable an attacker to perform actions using the privileges of the affected user or access session-specific information. This flaw is characterized as a persistence-layer validation gap and a defense-in-depth weakness.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85230

Affected Products

Misp