CVE-2026-103662
Deferred
Deferred - Pending Action
Reflected XSS in MISP Legacy Taxonomy Tag Management
Vulnerability report for CVE-2026-103662, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: CIRCL
Description
Description
MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).
The affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator's browser session.
Preconditions:
- The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.
- The victim must be an authenticated site administrator.
- The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).
Security impact:
- Execution of arbitrary client-side script in the context of the administrator's browser.
- Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.
- Potential for performing privileged actions on behalf of the administrator within the MISP interface.
Affected versions: <2.5.48.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| misp | misp | to 2.5.48 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |