Threats Tagged 'cve-2026-77751'
View all threats tagged with 'cve-2026-77751'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-77751'
Click on any threat for detailed analysis and mitigation recommendations
A path traversal vulnerability in MISP's handling of object template names during STIX 2 import and MISP-to-STIX 2 export allows crafted object names containing path traversal sequences to escape the intended template directory. This can lead to loading and interpreting unintended definition.json files from other filesystem locations, potentially disclosing local data or altering object metadata. The vulnerability arises because object names from untrusted STIX or MISP content were not properly validated before being used in filesystem paths. Patches introduce strict validation restricting object-template names to safe characters and replace invalid names with a generic placeholder, preventing traversal while preserving source information in comments. Join the discussion | GCVE Database | 08/21/2026, 12:30:31 UTC Added: 08/21/2026, 14:22:15 UTC |
0 CVE-2026-77751 is a path traversal vulnerability in misp-stix affecting the handling of MISP object template names during STIX 2 import and export. The vulnerability allows crafted object names containing path traversal sequences to escape the intended template directory and load arbitrary definition.json files accessible to the process. This can lead to unintended disclosure of local data and modification of object metadata. The issue is mitigated by patches that enforce strict validation of object-template names, restricting them to safe characters and replacing invalid names with a generic placeholder. Join the discussion | CVE Database V5 | 08/21/2026, 09:48:20 UTC Added: 08/21/2026, 10:07:50 UTC |
Showing 1 to 2 of 2 results