Executive brief
MISP, a threat intelligence platform, contains a vulnerability in its EventReport upload functionality where an authenticated user with basic permissions can enumerate files on the server by supplying arbitrary filesystem paths. The application returns distinct error messages revealing whether files exist and their type, allowing attackers to map the server's filesystem without reading actual file contents. This information disclosure can identify sensitive locations like configuration files or private keys that could be targeted in follow-up attacks.
Technical details
The EventReport::uploadPicture method processes a caller-supplied tmp_name field and invokes file_exists(), mime_content_type(), and exif_imagetype() before validating with is_uploaded_file(). An authenticated perm_add user can supply arbitrary filesystem paths, and distinct validation error messages leak file existence and type information. The vulnerability does not allow file read/write or code execution, but enables information disclosure through error-based enumeration.
Affected products
- MISP Project MISP
Timeline
- 2026-09-22: disclosed
- 2026-09-22: patched: Fix applied in commit 9a2a4ac to reject forged upload paths