Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103321— MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MISP 的事件图预览功能中存在一个存储型跨站脚本(XSS)漏洞。 事件图的预览图像字段在未经服务器端验证的情况下被接受并存储。在客户端,该存储值通过字符串拼接的方式渲染到 HTML 元素的 属性中,攻击者可构造恶意值以突破属性上下文限制,从而注入任意脚本。 前提条件: 一个已认证的 MISP 用户,具备创建或修改事件图条目的权限。 另一个用户(受害者),其查看事件图并触发预览弹出框。 影响: 在受害者的浏览器中,于 MISP 应用上下文内执行任意 JavaScript 代码。 可能导致窃取受害者的会话令牌、Coo

CVSS 8.3 · High EPSS 0.36% · P27

Possible ATT&CK Techniques 1 AI

T1059.007 · JavaScript

Affected Version Matrix 1

VendorProduct Version RangeStatus
MISP MISP < 2.5.48 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103321

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image
Source: CVE Program / CVE List V5
Vulnerability Description
MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script. Preconditions: - An authenticated MISP user with the ability to create or modify an event graph entry. - A second user (the victim) who views the event graph and triggers the preview popover. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser. - Potential for performing actions on behalf of the victim within the MISP application. Affected: MISP versions prior to the fix (commit applied after v2.5.48).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-103321

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103321

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-103321 (1)

Same Patch Batch · MISP · 2026-09-30 · 6 CVEs total

CVE-2026-103235 8.7 HIGH MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events
CVE-2026-103239 8.6 HIGH MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection
CVE-2026-103237 8.3 HIGH MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows
CVE-2026-103388 6.2 MEDIUM MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field
CVE-2026-103389 6.2 MEDIUM MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph

IV. Related Vulnerabilities

V. Comments for CVE-2026-103321

No comments yet


Leave a comment