Executive brief
MISP, an open-source threat intelligence platform, contains a reflected cross-site scripting vulnerability in its event export feature. An unauthenticated attacker can craft a malicious URL that, when visited by an authenticated user, executes arbitrary JavaScript in the user's browser session. This could allow the attacker to hijack the user's session, steal sensitive data, or perform unauthorized actions within MISP.
Technical details
The vulnerability exists in the event REST search export confirmation form (eventRestSearchExportConfirmationForm.ctp) where URL-supplied event IDs are rendered into a JavaScript string literal using PHP's json_encode() without hex-encoding flags. Since json_encode() does not escape single quotes by default, an attacker can inject a single quote to break out of the string literal and inject arbitrary JavaScript code. The attack requires an authenticated victim to click a malicious link, and affects the Default and UiBeta themes but not the Overmind theme which properly escapes the value.
Affected products
- MISP Project MISP unspecified
Timeline
- 2026-09-22: disclosed