Cross-Site Scripting Vulnerability in MISP TAXII Object Viewer
CVE-2026-104906
What is CVE-2026-104906?
The MISP application is exposed to a cross-site scripting (XSS) vulnerability found in the TAXII object viewer. This issue arises when remote TAXII objects are displayed, as the JSON content of string properties is rendered directly into an HTML pre block without proper HTML encoding. An attacker can exploit this by publishing a malicious TAXII object that the victim's MISP instance subscribes to, allowing them to execute arbitrary JavaScript within the context of the victim's MISP session. This vulnerability requires the victim to be an authenticated MISP user with access to the TAXII object viewer and to interact with the crafted TAXII object, resulting in the potential theft of session tokens, API keys, or other sensitive data available in the MISP user interface, as well as the ability to maneuver actions on behalf of the authenticated user.
Affected Version(s)
MISP 0 < 2.5.48
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
