Reflected XSS Vulnerability in MISP by MISP Project
CVE-2026-103664
4.8MEDIUM
What is CVE-2026-103664?
MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel, where the user-supplied seed path parameter is directly inserted into inline JavaScript without proper sanitization. This oversight allows attackers to craft malicious URLs that, when accessed by authenticated MISP users, execute arbitrary JavaScript in their browsers. This could lead to potential theft of session tokens and sensitive data, as well as manipulation of the analyst data interface. To mitigate this risk, users are advised to upgrade to MISP version 2.5.48 or later.
Affected Version(s)
MISP 0 < 2.5.48
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jeroen Pinoy
iglocska
Claude Opus 5.5 (1M context)
