Stored XSS Vulnerability in MISP Galaxy Icon Handling
CVE-2026-103389

6.2MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103389?

MISP is affected by a stored cross-site scripting (XSS) vulnerability tied to the handling of galaxy icons. This occurs when the icon field of a galaxy object is saved without server-side validation. The stored data is then directly integrated into HTML markup by D3-based rendering scripts, allowing a user with editing permissions to insert malicious scripts. Following this, any user who views the correlation graph of an event associated with that galaxy could have malicious scripts executed in their browser environment, potentially leading to stolen session credentials, unauthorized data manipulation, or unintended actions initiated on behalf of the user. The vulnerability affects both the default and Overmind themes of MISP, posing significant risks for users. Users are encouraged to apply the security patch to mitigate these risks.

Affected Version(s)

MISP 0 < 2.5.48

References

CVSS V4

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Fable 5.1
.