URL Validation Flaw in MISP Dashboard Button Widget Exposed by Vendor
CVE-2026-10856
5.1MEDIUM
What is CVE-2026-10856?
The MISP dashboard button widget contained a URL validation flaw that allowed crafted URLs to bypass security measures, permitting attackers to redirect users to malicious external sites. The widget incorrectly accepted URLs starting with certain patterns, such as a backslash, posing serious risks for phishing and credential theft. By exploiting this flaw, attackers could create deceptive dashboard buttons that appeared to direct users within the application while actually linking them to attacker-controlled domains. Security measures have since been implemented to mitigate this issue by enforcing strict validation rules on URLs.
Affected Version(s)
misp 0 <= 2.5.38
