CVE-2026-104907 PUBLISHED

MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler

Assigner: CIRCL
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.

Preconditions:

  • A linked/remote MISP server is configured and connected to the local instance.

  • The linked server supplies a crafted tag ID in an event.

  • An authenticated user views the event preview and interacts with the affected tag element.

Impact:

  • Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.

Affected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
CVSS Score: 4.8

Product Status

Vendor MISP
Product MISP
Versions
  • affected from 0 to 2.5.48 (excl.)

Solutions

The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.

Credits

  • Jeroen Pinoy reporter
  • iglocska remediation developer
  • Claude Opus 5.5 (1M context) remediation developer

References

Problem Types

  • CWE-79 Cross-site Scripting (XSS) CWE
  • CWE-116 Improper Encoding or Escaping of Output CWE

Impacts

  • CAPEC-1 Cross Site Scripting
  • CAPEC-126 Exploiting Incorrectly Handled Special/Control Characters