Junglewise Threat Intelligence

CVE-2026-44364: MISP misp-modules CSRF in website home blueprint

CVE-2026-44364 · Severity: critical · CVSS 4 · Published 2026-05-13

Technologies: MISP Project Misp-Modules. Vendors: MISP Project, PyPI.

Executive brief

A security vulnerability exists in the MISP Modules website, a tool used for expanding the functionality of the MISP threat intelligence platform. An attacker could trick an authenticated user into performing unintended actions, such as modifying session data or queries, without their knowledge. This could lead to unauthorized changes in how threat data is processed or viewed within the system.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the misp-modules website due to the 'home' blueprint being explicitly exempted from CSRF protection. An attacker can exploit this by inducing an authenticated user to visit a malicious site that triggers a request to the vulnerable endpoint. Successful exploitation allows the attacker to modify session query data in the context of the authenticated user. The vulnerability is addressed by enabling CSRF protection for the affected blueprint and hardening the query parsing logic.

Affected products

  • MISP Project misp-modules <= 3.0.7

Timeline

  • 2026-04-29: disclosed: Initial disclosure to MISP/misp-modules
  • 2026-05-06: advisory: GitHub Advisory published
  • 2026-05-13: advisory: NVD published CVE-2026-44364

References

Related threats