PT-2026-96721 · Misp · Misp

·

CVE-2026-95659

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.47
Description A reflected cross-site scripting (XSS) issue exists in the AnalystDataController::viewForObject action. The method accepts a parent object type parameter from the URL without validation and passes it to the Overmind-themed AnalystData thread view element. This value is then interpolated into translated strings and rendered in the HTML response without output encoding. An authenticated attacker can induce a victim to visit a crafted URL to execute arbitrary JavaScript in the victim's browser within the application context, potentially allowing the attacker to read session data, manipulate the page, or perform actions on behalf of the victim. The affected components are the AnalystData controller and the Overmind theme's AnalystData thread element.
Recommendations Update to version 2.5.47 or later.

Fix

Improper Encoding or Escaping of Output

XSS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95659

Affected Products

Misp