MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. (CVE-2026-104906)
MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer that allows execution of arbitrary JavaScript when viewing crafted TAXII objects. This occurs because JSON string properties are rendered without HTML encoding. An authenticated user with access to the TAXII object viewer who opens a malicious TAXII object can have scripts executed in their browser context, potentially leading to session token theft or unauthorized actions. The vulnerability affects MISP versions prior to 2.5.48.
AI Analysis
Technical Summary
The vulnerability in MISP's TAXII object viewer arises from improper handling of JSON content in string properties, which are rendered directly into an HTML pre block without HTML encoding. This allows an attacker who can influence TAXII object content to inject arbitrary HTML or JavaScript. The attack requires the victim to be an authenticated MISP user with access to the TAXII object viewer and to open the malicious object. Successful exploitation can lead to arbitrary script execution within the victim's MISP session context, risking session token theft, API key exposure, and unauthorized actions performed as the victim user. The affected versions are all MISP versions before 2.5.48.
Potential Impact
Arbitrary JavaScript execution in the context of the victim's MISP session can lead to theft of session tokens, API keys, or other sensitive data accessible via the MISP interface. Additionally, attackers can perform actions on behalf of the authenticated user, potentially compromising the integrity and confidentiality of the MISP environment.
Mitigation Recommendations
A fix is available in MISP version 2.5.48. Users should upgrade to version 2.5.48 or later to remediate this vulnerability. Until upgraded, users should avoid opening TAXII objects from untrusted sources. No vendor advisory content was provided, so check the official MISP release notes or advisories for confirmation and additional guidance.
MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. (CVE-2026-104906)
Description
MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer that allows execution of arbitrary JavaScript when viewing crafted TAXII objects. This occurs because JSON string properties are rendered without HTML encoding. An authenticated user with access to the TAXII object viewer who opens a malicious TAXII object can have scripts executed in their browser context, potentially leading to session token theft or unauthorized actions. The vulnerability affects MISP versions prior to 2.5.48.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in MISP's TAXII object viewer arises from improper handling of JSON content in string properties, which are rendered directly into an HTML pre block without HTML encoding. This allows an attacker who can influence TAXII object content to inject arbitrary HTML or JavaScript. The attack requires the victim to be an authenticated MISP user with access to the TAXII object viewer and to open the malicious object. Successful exploitation can lead to arbitrary script execution within the victim's MISP session context, risking session token theft, API key exposure, and unauthorized actions performed as the victim user. The affected versions are all MISP versions before 2.5.48.
Potential Impact
Arbitrary JavaScript execution in the context of the victim's MISP session can lead to theft of session tokens, API keys, or other sensitive data accessible via the MISP interface. Additionally, attackers can perform actions on behalf of the authenticated user, potentially compromising the integrity and confidentiality of the MISP environment.
Mitigation Recommendations
A fix is available in MISP version 2.5.48. Users should upgrade to version 2.5.48 or later to remediate this vulnerability. Until upgraded, users should avoid opening TAXII objects from untrusted sources. No vendor advisory content was provided, so check the official MISP release notes or advisories for confirmation and additional guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x6q8-3wfm-g2w6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-104906"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6ac00d21a43b0b3b89fb133f
Added to database: 10/02/2026, 19:59:29 UTC
Last enriched: 10/02/2026, 20:17:10 UTC
Last updated: 10/03/2026, 03:08:20 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.