Executive brief
MISP, a threat intelligence sharing platform, was configured to enable PHP's phar stream wrapper by default, which allows attackers who can control filesystem paths to trigger arbitrary code execution through deserialization or direct phar access. An attacker could exploit this to run malicious code with the privileges of the web server process, potentially compromising the entire threat intelligence platform and any data it contains.
Technical details
The vulnerability exploits PHP's phar stream wrapper, which is registered by default in MISP's entry points. This wrapper causes any filesystem operation on an attacker-influenced path to trigger implicit unserialize() calls (deserialization sink) and allows direct execution of code within relocated phar archives. MISP itself contains no legitimate use of phar archives, making the wrapper purely an attack surface that was unintentionally available to any attacker who could inject or control filesystem path arguments.
Affected products
- MISP Project MISP
Timeline
- 2026-09-22: disclosed: Vulnerability published on NVD
- 2026-09-22: patched: Fix committed to unregister phar stream wrapper in entry points