Junglewise Threat Intelligence

CVE-2026-88921: MISP HTML injection in MISPElementHTMLFormatterTool

CVE-2026-88921 · Severity: info · CVSS 0 · Published 2026-09-10

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP is a threat intelligence platform used to share and manage indicators of compromise. The platform contains an HTML injection vulnerability in its PDF report export feature that allows authenticated users to embed arbitrary HTML markup in attributes, objects, and tags. When a report is exported to PDF, this unescaped content could alter the document's visual appearance, break its structure, or inject malicious markup depending on the PDF rendering engine used.

Technical details

The MISPElementHTMLFormatterTool component's attribute(), objectAttribute(), object(), and tag() methods perform unsafe interpolation of user-controlled fields (attribute type/value, object name/relation, tag name/color) directly into HTML templates without entity encoding. An authenticated actor with write access to MISP elements can inject arbitrary HTML markup that gets rendered as live HTML during PDF export via the convert_markdown_to_pdf module. Additionally, the attribute() method uses hardcoded sample values ("domain-ip", "google.com") instead of format placeholders, causing all plain attribute references in exported PDFs to display sample text rather than actual indicator values. Attack requires authentication, MISP element write access, and a subsequent PDF report export containing those elements.

Affected products

  • MISP Project MISP ≤2.5.45

Timeline

  • 2026-09-10: disclosed