HTML Injection Vulnerability in MISP's PDF Export Functionality
CVE-2026-88921
What is CVE-2026-88921?
MISP's PDF export functionality is susceptible to an HTML injection vulnerability through the MISPElementHTMLFormatterTool. By exploiting this flaw, authenticated users with permissions to create or modify MISP attributes, objects, or tags can inject arbitrary HTML into the exported PDF reports. This occurs due to the failure to properly encode user-controlled fields during HTML rendering, allowing potential manipulation of document structure or visual content. Furthermore, the use of hardcoded samples instead of dynamic values in certain attributes constitutes a data integrity defect, where exported reports may misleadingly represent indicator values. The combination of these issues raises concerns about the integrity and security of the exported documentation.
Affected Version(s)
MISP < 2.5.46
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
