« Volver al listado

CVE-2026-103321

Estado: AplazadaAlta (8.3)—

MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.

The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.

Preconditions:

- An authenticated MISP user with the ability to create or modify an event graph entry.

- A second user (the victim) who views the event graph and triggers the preview popover.

Impact:

- Execution of arbitrary JavaScript in the victim's browser within the MISP application context.

Leer descripción completaMostrar menos

- Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser.

- Potential for performing actions on behalf of the victim within the MISP application.

Affected: MISP versions prior to the fix (commit applied after v2.5.48).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-103321",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-103321",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-30T12:44:13.205587Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "PASSIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "HIGH",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "HIGH",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/MISP/MISP",
          "vendor": "MISP",
          "modules": [
            "EventGraph model",
            "event-graph.js client-side rendering"
          ],
          "product": "MISP",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.5.48",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "app/Model/EventGraph.php",
            "app/webroot/js/event-graph.js"
          ]
        }
      ]
    }
  ],
  "published": "2026-09-30T13:17:18.463",
  "references": [
    {
      "url": "https://github.com/MISP/MISP/commit/92c7ccc43",
      "source": "5a6e4751-2f3f-4070-9419-94fb35b644e8"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        },
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\n\nThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\n\nPreconditions:\n\n- An authenticated MISP user with the ability to create or modify an event graph entry.\n\n- A second user (the victim) who views the event graph and triggers the preview popover.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim's browser within the MISP application context.\n\n- Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser.\n\n- Potential for performing actions on behalf of the victim within the MISP application.\n\nAffected: MISP versions prior to the fix (commit applied after v2.5.48)."
    }
  ],
  "lastModified": "2026-09-30T13:17:18.603",
  "sourceIdentifier": "5a6e4751-2f3f-4070-9419-94fb35b644e8"
}