CVE-2026-103388
Deferred Deferred - Pending Action

Stored XSS in MISP Galaxy Cluster Source Field

Vulnerability report for CVE-2026-103388, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: CIRCL

Description

MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source. When another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim's browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim. Preconditions: - Attacker must hold galaxy editor privileges (local or via sync). - Victim must view the affected cluster and click the malicious link. Impact: - Stored cross-site scripting (XSS) in the victim's browser. - Potential session theft, credential harvesting, or unauthorized actions within the MISP application. Affected: <2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves stored cross-site scripting (XSS) in MISP where a user with galaxy editor privileges can insert a javascript: URL as a Galaxy Cluster source. When rendered as a clickable link, clicking it executes malicious JavaScript in the victim's browser, enabling session hijacking or data theft.

Detection Guidance

Check MISP instances for galaxy clusters with source fields containing javascript: URLs. Inspect browser console logs for unexpected script executions when viewing galaxy clusters. Review MISP logs for unauthorized actions or session anomalies.

Impact Analysis

If you click the malicious link, an attacker could hijack your session, steal credentials, or perform unauthorized actions within MISP on your behalf. This requires you to view the affected cluster and click the link.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later. Implement input validation to reject non-http(s) URLs in galaxy cluster sources. Restrict galaxy editor privileges to trusted users only. Monitor for suspicious activities in MISP logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103388. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart