Executive brief
MISP is a threat intelligence platform used by security teams to share and analyze malware indicators and attack data. A vulnerability in the dashboard's button widget allows authenticated users to inject malicious URLs containing JavaScript code into dashboard configurations, which could be executed in the context of another user's session. Although MISP's runtime validation provides some protection, this persistence-layer gap could allow attackers to bypass mitigations and execute arbitrary actions with victim user privileges.
Technical details
The vulnerability is a persistent unsafe URL injection in MISP's ButtonWidget configuration validation. Dashboard widget URLs are validated at render time but were not validated when the configuration was saved to persistent storage, allowing authenticated users to store arbitrary URLs including javascript: scheme URIs. An attacker with dashboard modification privileges could inject malicious JavaScript URLs that, if not caught by runtime validation during rendering or navigation, could execute in the MISP security context with the victim user's privileges. The patch introduces canonical URL schema validation that enforces absolute paths on the current MISP instance or same-origin full URLs at save time, rejecting javascript: URIs, external origins, and malformed URL forms before persistence.
Affected products
- MISP Project MISP <UNKNOWN>
Timeline
- 2026-09-03: disclosed