Executive brief
MISP is an open-source threat intelligence platform used by security teams to share and analyze malware samples and attack indicators. A reflected cross-site scripting vulnerability in the event filtering interface allows an attacker to inject malicious JavaScript into a specially crafted URL that executes with the privileges of an authenticated user, potentially leading to unauthorized access, data modification, or other actions based on the victim's permissions.
Technical details
The vulnerability is a reflected XSS in the event attribute filtering query builder, specifically in the taggedAttributes and galaxyAttachedAttributes URL parameters. These parameters are inserted into JSON-encoded data without HTML escaping and then embedded inside a <script> element. Because JsonTool::encode() uses JSON_UNESCAPED_SLASHES, an attacker can include a literal </script> sequence in the parameter to break out of the script element and inject arbitrary HTML or JavaScript. The attack requires an authenticated user to follow a crafted URL (social engineering), but no other preconditions. Exploitation allows execution of JavaScript in the victim's authenticated session context. The vulnerability is fixed by applying HTML escaping with h() to both scalar and array values before DOM insertion.
Affected products
- MISP Project MISP
Timeline
- 2026-09-03: disclosed: CVE-2026-85227 published
- patched: Fix applied via commit de51a16 (HTML escaping with h() applied to taggedAttributes and galaxyAttachedAttributes)