Stored XSS Vulnerability in MISP Galaxy Cluster by MISP
CVE-2026-103388

6.2MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103388?

The MISP Galaxy Cluster feature is susceptible to a stored cross-site scripting (XSS) vulnerability. When a user with galaxy editor privileges stores a JavaScript URL in the source field, it is rendered as a clickable link. This allows an attacker to potentially execute malicious scripts in the context of another user's browser. Upon clicking the link, the victim may unknowingly execute the embedded script, leading to session hijacking, data exfiltration, or unauthorized actions within the MISP application. It is essential for users to update to version 2.5.48 or later to mitigate this risk.

Affected Version(s)

MISP 0 < 2.5.48

References

CVSS V4

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Opus 5.5 (1M context)
.