Stored XSS Vulnerability in MISP Galaxy Icon Handling
CVE-2026-103389
What is CVE-2026-103389?
MISP is affected by a stored cross-site scripting (XSS) vulnerability tied to the handling of galaxy icons. This occurs when the icon field of a galaxy object is saved without server-side validation. The stored data is then directly integrated into HTML markup by D3-based rendering scripts, allowing a user with editing permissions to insert malicious scripts. Following this, any user who views the correlation graph of an event associated with that galaxy could have malicious scripts executed in their browser environment, potentially leading to stolen session credentials, unauthorized data manipulation, or unintended actions initiated on behalf of the user. The vulnerability affects both the default and Overmind themes of MISP, posing significant risks for users. Users are encouraged to apply the security patch to mitigate these risks.
Affected Version(s)
MISP 0 < 2.5.48
