CVE-2026-103664
Deferred Deferred - Pending Action

Reflected XSS in MISP Analyst Data Notes Panel

Vulnerability report for CVE-2026-103664, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: CIRCL

Description

MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement. An attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim. Preconditions: - The victim must be authenticated to MISP and access the analyst data view for an attribute or object. - The attacker must supply a malicious seed value in the URL path. Impact: - Execution of arbitrary JavaScript in the victim's browser session. - Potential theft of session credentials or sensitive data visible in the page. - Manipulation of the analyst data interface. Affected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter from the URL is passed directly into inline JavaScript without sanitization. An attacker can trick an authenticated user into visiting a malicious URL to inject arbitrary JavaScript that runs in the victim's browser.

Detection Guidance

Detecting this vulnerability requires checking for unpatched MISP versions and monitoring for unusual URL parameters. Inspect MISP logs for requests containing 'seed' in the URL path. Use commands like 'grep -r "seed" /var/www/MISP/app/tmp/logs/' to search logs for suspicious activity. Ensure your MISP instance is updated to a version post commit 58925dbf0.

Impact Analysis

This vulnerability allows an attacker to execute arbitrary JavaScript in your browser session if you are authenticated to MISP and access the analyst data view. This could lead to theft of session tokens or sensitive data visible on the page, and manipulation of the analyst data interface.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling attackers to steal session tokens or sensitive data visible in the MISP interface. Such data exposure may violate confidentiality requirements under these regulations.

Mitigation Strategies

Immediately update MISP to a version that includes commit 58925dbf0 or later. If immediate update is not possible, restrict access to the analyst data view until patched. Educate users to avoid clicking untrusted links and monitor for unusual browser behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103664. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart