Description
MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output encoding.

A malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks.

Preconditions:

- The victim must be an authenticated user of the host MISP instance.

- A linked server must be configured on the host instance.

- The victim must navigate to the ID Translator page for a given event.

Affected versions: <2.5.48.
Published: 2026-10-02
Score: 5.1 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

The vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Description MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output encoding. A malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks. Preconditions: - The victim must be an authenticated user of the host MISP instance. - A linked server must be configured on the host instance. - The victim must navigate to the ID Translator page for a given event. Affected versions: <2.5.48.
Title MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server
First Time appeared Misp
Misp misp
Weaknesses CWE-79
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-02T16:15:49.327Z

Reserved: 2026-10-02T15:21:46.840Z

Link: CVE-2026-104901

cve-icon Vulnrichment

Updated: 2026-10-02T16:15:42.544Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:47.797

Modified: 2026-10-02T17:17:04.413

Link: CVE-2026-104901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')