A malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks.
Preconditions:
- The victim must be an authenticated user of the host MISP instance.
- A linked server must be configured on the host instance.
- The victim must navigate to the ID Translator page for a given event.
Affected versions: <2.5.48.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
The vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/MISP/MISP/commit/bd5e80c84 |
|
Fri, 02 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output encoding. A malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks. Preconditions: - The victim must be an authenticated user of the host MISP instance. - A linked server must be configured on the host instance. - The victim must navigate to the ID Translator page for a given event. Affected versions: <2.5.48. | |
| Title | MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server | |
| First Time appeared |
Misp
Misp misp |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Misp
Misp misp |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CIRCL
Published:
Updated: 2026-10-02T16:15:49.327Z
Reserved: 2026-10-02T15:21:46.840Z
Link: CVE-2026-104901
No data.
Status : Deferred
Published: 2026-10-02T16:16:47.797
Modified: 2026-10-02T16:16:47.900
Link: CVE-2026-104901
No data.
OpenCVE Enrichment
Updated: 2026-10-02T16:30:14Z