DOM-based Cross-Site Scripting in MISP Contextual Menu by MISP Threat Intelligence
CVE-2026-94373
6.3MEDIUM
What is CVE-2026-94373?
MISP is vulnerable to a DOM-based cross-site scripting (XSS) flaw in its contextual menu JavaScript component. The vulnerability arises from the ContextualMenu class, which incorrectly assigns user-controlled values to the innerHTML property of HTML elements. This allows untrusted strings to be interpreted as live DOM content, enabling attackers to inject malicious HTML or JavaScript. If an attacker successfully manipulates the data rendered in the contextual menu, they can execute scripts in the browser of an authenticated user, potentially leading to session hijacking, unauthorized actions, or data exfiltration.
Affected Version(s)
MISP 0 < 2.5.47
