CVE-2026-104907: medium-severity vulnerability in MISP
MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.8epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.
Preconditions:
- A linked/remote MISP server is configured and connected to the local instance.
- The linked server supplies a crafted tag ID in an event.
- An authenticated user views the event preview and interacts with the affected tag element.
Impact:
- Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.
Affected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Affected products
MISP · MISPRelated CVEs — MISP
In the same product, most dangerous first.
CVE-2026-95701MEDIUMMISP Path Traversal via Organization Name in Org-Statistics Logo CheckEPSS 0.8%CVE-2026-44381CRITICALMISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listingsEPSS 0.8%CVE-2026-95698MEDIUMMISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization NameEPSS 0.7%CVE-2026-39962HIGHLDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variableEPSS 0.7%CVE-2026-106513MEDIUMMISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via UI/API Configuration ChangeEPSS 0.6%CVE-2026-90961CRITICALMISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String CredentialsEPSS 0.6%