CVE-2026-103389
Deferred Deferred - Pending Action

Stored XSS in MISP Galaxy Icon Handling

Vulnerability report for CVE-2026-103389, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: CIRCL

Description

MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method. A user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session. Impact: - Arbitrary script execution in the context of the victim's MISP session - Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim - Affects both the default and Overmind UI themes Affected versions: <2.5.48

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in MISP where a user with the perm_galaxy_editor permission can inject malicious HTML or JavaScript into the galaxy icon field. The injected script executes in the browser of any user viewing the correlation graph of an event containing the affected galaxy cluster.

Detection Guidance

To detect this vulnerability, check MISP versions below 2.5.48. Review galaxy icon fields in galaxy objects for suspicious HTML or JavaScript content. Inspect correlation graph rendering scripts for improper HTML insertion. Use MISP logs to track edits by users with perm_galaxy_editor permission.

Impact Analysis

This vulnerability allows arbitrary script execution in your MISP session. An attacker could steal your session credentials, manipulate displayed data, or perform actions on your behalf without your knowledge.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR's data protection principles or HIPAA's security requirements for protected health information. The arbitrary script execution risk could enable data exfiltration or manipulation, undermining compliance with these regulations.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later. Remove or sanitize any malicious icon values in galaxy objects. Restrict perm_galaxy_editor permission to trusted users only. Monitor for unusual activity in correlation graphs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103389. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart