Description
MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.

Preconditions:

- A linked/remote MISP server is configured and connected to the local instance.

- The linked server supplies a crafted tag ID in an event.

- An authenticated user views the event preview and interacts with the affected tag element.

Impact:

- Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.

Affected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).
Published: 2026-10-02
Score: 4.8 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script. Preconditions: - A linked/remote MISP server is configured and connected to the local instance. - The linked server supplies a crafted tag ID in an event. - An authenticated user views the event preview and interacts with the affected tag element. Impact: - Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user. Affected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).
Title MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler
First Time appeared Misp
Misp misp
Weaknesses CWE-116
CWE-79
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-02T16:18:12.403Z

Reserved: 2026-10-02T15:51:32.541Z

Link: CVE-2026-104907

cve-icon Vulnrichment

Updated: 2026-10-02T16:18:07.391Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:48.253

Modified: 2026-10-02T17:17:04.823

Link: CVE-2026-104907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:45:17Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')