CVE-2026-103389Medium· 6.2▾ SunlitMISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture en…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.
A user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.
Impact:
Arbitrary script execution in the context of the victim's MISP session
Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim
Affects both the default and Overmind UI themes
Affected versions: <2.5.48
MISP < 2.5.48The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103321High· 8.3MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation
CVE-2026-95659Medium· 4.8MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action
CVE-2026-85230Medium· 5.4A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration
CVE-2023-28607Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
CVE-2023-28606Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
CVE-2023-24027Medium· 6.1In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.