Executive brief
MISP, a threat intelligence platform, contains a vulnerability in its organization logo retrieval feature that allows authenticated users to exploit directory traversal. An attacker can craft an organization name with path traversal sequences (such as ../../) to read arbitrary PNG and SVG files on the server, or probe for file existence. This requires authentication and event import privileges but does not require interaction from other users.
Technical details
The findOrgImage method in OrgImgHelper constructs filesystem paths by concatenating user-supplied organization identifiers (name, ID, or UUID) with a fixed directory prefix and file extension (.png or .svg) without sanitizing path traversal sequences. An authenticated user importing an event with a crafted organization name containing ../ segments can resolve paths outside the intended org-image directory, enabling both an arbitrary file existence oracle via file_exists() and limited file read access for files matching the PNG or SVG extensions.
Affected products
- MISP MISP before fix commit e009860
Timeline
- 2026-09-22: disclosed