Reflected XSS Vulnerability in MISP by MISP Project
CVE-2026-103664

4.8MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103664?

MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel, where the user-supplied seed path parameter is directly inserted into inline JavaScript without proper sanitization. This oversight allows attackers to craft malicious URLs that, when accessed by authenticated MISP users, execute arbitrary JavaScript in their browsers. This could lead to potential theft of session tokens and sensitive data, as well as manipulation of the analyst data interface. To mitigate this risk, users are advised to upgrade to MISP version 2.5.48 or later.

Affected Version(s)

MISP 0 < 2.5.48

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Opus 5.5 (1M context)
.