Junglewise Threat Intelligence

CVE-2026-8080: MISP Stored XSS in template element attribute handling

CVE-2026-8080 · Severity: medium · CVSS 5.4 · Published 2026-05-07

Technologies: MISP Project MISP, Misp. Vendors: MISP Project, Misp.

Executive brief

MISP, an open-source threat intelligence platform, is vulnerable to a security flaw in its legacy templating engine. An attacker with basic user permissions can inject malicious scripts into template attributes, which could then execute in the browsers of other users. This could lead to unauthorized actions being performed on behalf of legitimate users or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in MISP versions prior to 2.5.37 within the TemplateElementAttribute handling logic. The application failed to validate the 'type' and 'category' fields against known MISP definitions, allowing arbitrary values to be stored in the database. An authenticated attacker with permissions to create or modify template element attributes can inject malicious JavaScript into these fields. When another user views the affected template, the payload executes in their browser context. This affects the legacy templating engine, which was disabled in 2.5.37 and is scheduled for removal in 2.5.38.

Affected products

  • MISP Project MISP before 2.5.37

Timeline

  • 2026-05-07: disclosed
  • 2026-05-07: advisory
  • 2026-05-07: patched: Fixed in version 2.5.37

References

Related threats