---
id: CVE-2026-103389
title: >-
  MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy
  icon handling path
summary: >-
  MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy
  icon handling path. The icon field of a galaxy object was persisted without
  any server-side validation through the galaxy add, edit, and sync/import
  capture en…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'
cwe:
  - CWE-20
  - CWE-79
vendor: MISP
product: MISP
affected:
  - MISP < 2.5.48
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:17:09.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103389'
references:
  - url: 'https://github.com/MISP/MISP/commit/8ea5783dd'
    label: 5a6e4751-2f3f-4070-9419-94fb35b644e8
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-30T14:58:27.715153Z'
cvssSource: cna
ingestedAt: '2026-09-30T15:07:05.389Z'
---

## Overview

MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.

A user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.

Impact:

- Arbitrary script execution in the context of the victim's MISP session

- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim

- Affects both the default and Overmind UI themes

Affected versions: <2.5.48

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
