Executive brief
MISP's sachertortephp library contains a Server-Side Request Forgery (SSRF) vulnerability in its XML parsing utility. A logic error in the condition that gates network access allows an attacker to force the application to fetch content from attacker-controlled or internal URLs via HTTPS, even when remote fetching is supposed to be disabled. The fetched response is then parsed as XML, potentially exposing sensitive data from internal services or external systems.
Technical details
The Xml::build() static method in lib/Cake/Utility/Xml.php uses a conditional with a logical operator precedence error to gate network-based XML fetching. The condition ($options['readFile'] && strpos($input, 'http://') === 0 || strpos($input, 'https://') === 0) evaluates due to && having higher precedence than ||, resulting in the https:// check not being properly gated by the readFile flag. An attacker who can control the $input parameter can pass a string starting with https:// to trigger an outbound network request via HttpSocket (which follows up to 10 redirects) regardless of the readFile option setting. The fetched response is parsed as XML and may be returned to the attacker, enabling SSRF with information-disclosure impact. Exploitation requires that the Xml::build() code path be reachable with attacker-controlled input.
Affected products
- MISP sachertortephp <UNKNOWN>
Timeline
- 2026-09-17: disclosed