Executive brief
MISP, a threat intelligence sharing platform, contains a stored cross-site scripting vulnerability in the admin email composition interface. An attacker with the ability to modify the organization name setting can inject malicious JavaScript that executes when other authenticated administrators access the email composition screen, potentially allowing session hijacking or unauthorized actions on their behalf.
Technical details
A stored XSS vulnerability exists due to insufficient output encoding of the MISP.org organization name setting when interpolated into a JavaScript string literal without escaping. An attacker with permission to set the organization name can inject arbitrary JavaScript using quote or backslash characters to break out of the string context. The injected payload executes in the browser of any authenticated user who subsequently loads the admin email composition page.
Affected products
- MISP MISP
Timeline
- 2026-09-22: disclosed
- 2026-09-22: patched: Fix deployed via commit 5d6ace6 escaping organization name with json_encode in admin_email.ctp