Executive brief
MISP is a threat intelligence platform used by organizations to share and analyze security information. The application allows users to configure a custom homepage URL that is used for post-login redirection. A flaw in the URL validation logic permitted attackers to craft protocol-relative URLs (e.g., //attacker.example) that bypass the check, causing the application to redirect users to external attacker-controlled sites after login, enabling phishing or session hijacking attacks.
Technical details
The vulnerability is an open redirect in the homepage setting validation. MISP validated user-configurable homepage paths by checking only whether they began with a forward slash (/), which is insufficient because protocol-relative URLs like //attacker.example also start with / but resolve to an external origin in browsers. The vulnerable homepage value is stored in user settings and later retrieved by post-login routing logic, which emits the unvalidated path to the Location HTTP header. The fix implements a comprehensive InternalRedirectValidator that rejects URLs containing a host, scheme, userinfo, unsafe leading sequences (//, /\), malformed URLs, and control characters, with revalidation on read to catch legacy unsafe values.
Affected products
- MISP MISP ≤2.5.45
Timeline
- 2026-09-07: disclosed: Published on NVD
- 2026-08-26: patched: Fix committed to repository