Junglewise Threat Intelligence

CVE-2026-94372: MISP stored cross-site scripting in Galaxies index page

CVE-2026-94372 · Severity: info · Published 2026-09-21

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP is an open-source threat intelligence sharing platform. A stored cross-site scripting (XSS) vulnerability in the default theme allows a user with tag-editing permissions to inject malicious code that executes when a site administrator views the Galaxies page, potentially allowing the attacker to hijack the administrator's session and perform actions on their behalf.

Technical details

The vulnerability exists in the default theme's Galaxies index page where unknown galaxy-cluster tag names are rendered in an informational notice without HTML entity encoding. An attacker with tag-editor privileges can craft a malicious misp-galaxy tag containing arbitrary JavaScript. When a site administrator views the Galaxies index page, the unescaped tag content is interpreted as executable markup in the administrator's browser session. The Overmind theme was not affected as it already applied HTML escaping.

Affected products

  • MISP Project MISP before 2.5.47

Timeline

  • 2026-09-21: disclosed: CVE-2026-94372 published
  • 2026-09: patched: Fix applied in version 2.5.47

References

Related threats