{"id":"CVE-2026-90957","title":"Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox.\n\n\nThe commit explains that SVG files are XML documents rather than passive bitmap images","summary":"Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox.\n\n\nThe commit explains that SVG files are XML documents rather than passive bitmap images. While scripts inside SVG do not execute when the …","severity":"medium","cvss":5.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","cwe":["CWE-79","CWE-693"],"vendor":"MISP","product":"MISP","affected":["MISP < 2.5.46"],"published":"2026-09-14","updated":"2026-09-16","sourceUpdated":"2026-09-16T13:42:47.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90957","references":[{"url":"https://github.com/MISP/MISP/commit/86496aecc","label":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}],"tags":["nvd","cve.org"],"epss":0.00396,"epssPercentile":0.31202,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T13:58:18.267352Z"},"cvssSource":"cna","ingestedAt":"2026-09-14T15:23:07.422Z","slug":"CVE-2026-90957","body":"## Overview\n\nAffected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox.\n\n\nThe commit explains that SVG files are XML documents rather than passive bitmap images. While scripts inside SVG do not execute when the SVG is rendered through a normal <img>, they can execute when the SVG is navigated to directly or embedded as a document. In that case, malicious <script> elements, event handlers, or javascript: URLs execute on the MISP origin with the viewer’s session.\n\n\nThe affected use cases include:\n\n\n\n - organisation SVG logos;\n - event-report SVG pictures.\n\n\n\n\n\n\nImportantly, the vulnerable behavior is on the serve path, not merely the upload path: the patch notes that a malicious SVG uploaded while SVG support was enabled could remain dangerous even after uploads were later disabled.\n\n\n\nVersion affected: ≤2.5.45\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":28.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}