Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104901— MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MISP 的 ID Translator(ID 翻译器)功能中存在跨站脚本(XSS)漏洞。当用户查看 ID Translator 页面时,应用程序会查询已链接(远程)MISP 服务器以获取相应的事件标识符。远程服务器返回的事件 ID 在 HTML 输出中未经适当的输出编码就直接渲染。 恶意或已被入侵的链接服务器可以返回包含任意 HTML 或 JavaScript 标记的构造事件 ID。这些标记会在主机组织中任何查看该 ID Translator 页面的用户的浏览器中渲染,从而导致会话劫持、凭证窃取或其他客户端攻击。

CVSS 5.1 · Medium EPSS 0.32% · P22

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 1

VendorProduct Version RangeStatus
MISP MISP < 2.5.48 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104901

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server
Source: CVE Program / CVE List V5
Vulnerability Description
MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output encoding. A malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks. Preconditions: - The victim must be an authenticated user of the host MISP instance. - A linked server must be configured on the host instance. - The victim must navigate to the ID Translator page for a given event. Affected versions: <2.5.48.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-104901

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104901

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104901 (1)

Same Patch Batch · MISP · 2026-10-02 · 8 CVEs total

CVE-2026-104908 7.1 HIGH MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and D
CVE-2026-104912 7.1 HIGH MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data
CVE-2026-104906 6.2 MEDIUM MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output
CVE-2026-104900 5.3 MEDIUM MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index
CVE-2026-104910 5.3 MEDIUM MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization
CVE-2026-104914 5.3 MEDIUM MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Pa
CVE-2026-104907 4.8 MEDIUM MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler

IV. Related Vulnerabilities

V. Comments for CVE-2026-104901

No comments yet


Leave a comment