DOM-based Cross-Site Scripting in MISP Contextual Menu by MISP Threat Intelligence
CVE-2026-94373

6.3MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-94373?

MISP is vulnerable to a DOM-based cross-site scripting (XSS) flaw in its contextual menu JavaScript component. The vulnerability arises from the ContextualMenu class, which incorrectly assigns user-controlled values to the innerHTML property of HTML elements. This allows untrusted strings to be interpreted as live DOM content, enabling attackers to inject malicious HTML or JavaScript. If an attacker successfully manipulates the data rendered in the contextual menu, they can execute scripts in the browser of an authenticated user, potentially leading to session hijacking, unauthorized actions, or data exfiltration.

Affected Version(s)

MISP 0 < 2.5.47

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iglocska
Jeroen Pinoy
David Andre
.