PT-2026-96090 · Misp · Misp

·

CVE-2026-94372

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.47
Description A stored cross-site scripting (XSS) issue exists in the default theme's Galaxies index page. During synchronization, when unknown custom or default galaxy clusters are detected, the system displays sample tag names in an informational notice for administrators. Because these tag names are inserted into the HTML output without HTML-entity encoding, a user with tag-editor privileges can create a malicious misp-galaxy tag containing arbitrary scripts. When an administrator views the Galaxies index page, the script executes in their browser session, potentially allowing the attacker to read session data or perform actions as the administrator. This issue is limited to the administrator's browser context and does not affect the server process. The Overmind theme is not affected as it implements HTML escaping.
Recommendations Update to version 2.5.47 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94372

Affected Products

Misp