CVE-2026-103321
Deferred Deferred - Pending Action

Stored XSS in MISP Event Graph Preview

Vulnerability report for CVE-2026-103321, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: CIRCL

Description

MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script. Preconditions: - An authenticated MISP user with the ability to create or modify an event graph entry. - A second user (the victim) who views the event graph and triggers the preview popover. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser. - Potential for performing actions on behalf of the victim within the MISP application. Affected: MISP versions prior to the fix (commit applied after v2.5.48).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has a stored cross-site scripting (XSS) vulnerability in its event graph preview feature. The preview image field was stored without server-side validation and rendered into an HTML img element's src attribute via string concatenation. This allows an attacker to inject malicious code that breaks out of the attribute context and executes arbitrary scripts in the victim's browser.

Detection Guidance

To detect this vulnerability, inspect MISP event graph preview functionality for improper input validation. Check if user-provided image fields are rendered directly into HTML img src attributes without sanitization. Review server-side code handling event graph previews for missing validation of base64-encoded PNG data URLs.

Impact Analysis

This vulnerability allows execution of arbitrary JavaScript in the victim's browser within the MISP application context. It could lead to theft of session tokens, cookies, or sensitive data accessible to the victim's browser. An attacker might also perform actions on behalf of the victim within MISP.

Mitigation Strategies

Apply the patch from the referenced commit (92c7ccc43) to validate event graph previews as base64-encoded PNG data URLs. Replace unsafe HTML string concatenation with DOM manipulation methods like jQuery's .prop() to set the src attribute. Ensure all user inputs in event graph fields are sanitized before rendering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103321. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart