{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-103321","assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","state":"PUBLISHED","assignerShortName":"CIRCL","dateReserved":"2026-09-30T12:18:54.232Z","datePublished":"2026-09-30T12:19:01.829Z","dateUpdated":"2026-09-30T12:44:22.064Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"],"modules":["EventGraph model","event-graph.js client-side rendering"],"product":"MISP","programFiles":["app/Model/EventGraph.php","app/webroot/js/event-graph.js"],"repo":"https://github.com/MISP/MISP","vendor":"MISP","versions":[{"lessThan":"2.5.48","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Bastien Bossiroy of NCIA"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 4.8"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.</p><p>The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.</p><p>Preconditions:</p><p>- An authenticated MISP user with the ability to create or modify an event graph entry.</p><p>- A second user (the victim) who views the event graph and triggers the preview popover.</p><p>Impact:</p><p>- Execution of arbitrary JavaScript in the victim's browser within the MISP application context.</p><p>- Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser.</p><p>- Potential for performing actions on behalf of the victim within the MISP application.</p><p>Affected: MISP versions prior to the fix (commit applied after v2.5.48).</p>"}],"value":"MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\n\nThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\n\nPreconditions:\n\n- An authenticated MISP user with the ability to create or modify an event graph entry.\n\n- A second user (the victim) who views the event graph and triggers the preview popover.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim's browser within the MISP application context.\n\n- Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser.\n\n- Potential for performing actions on behalf of the victim within the MISP application.\n\nAffected: MISP versions prior to the fix (commit applied after v2.5.48)."}],"impacts":[{"capecId":"CAPEC-1","descriptions":[{"lang":"en","value":"CAPEC-1 Cross Site Scripting (XSS)"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.3,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL","dateUpdated":"2026-09-30T12:19:01.829Z"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/92c7ccc43"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.</p>"}],"value":"The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML."}],"title":"MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"full","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["The affected version range is inferred from the tag_version_boundary (v2.5.48 with 43 commits after the fix); the exact fixed release version is not stated in the patch metadata.","PR:L assumes the attacker needs at least a basic authenticated MISP account to create or modify an event graph entry; the patch does not specify the exact permission level required.","UI:P assumes the victim triggers the XSS by viewing the event graph preview as part of normal workflow (hovering the plot button), which is a passive interaction rather than an active click on a crafted link.","The CAPEC-1 mapping is direct and unambiguous given the explicit stored XSS identification in the commit message.","The Co-Authored-By line referencing Claude Opus 4.8 is treated as a tool credit per the commit metadata; it is not a human contributor."],"capecRationale":[{"capecId":"CAPEC-1","rationale":"The patch directly addresses a stored XSS where attacker-controlled data is rendered into a web page without proper encoding or validation. CAPEC-1 is the canonical attack pattern for XSS and is the closest match. No uncertainty in this mapping; the commit message explicitly identifies the issue as stored XSS."}],"commit":"92c7ccc4398a64e61699bd79fb4010703616fc59","confidence":"high","credits":[{"lang":"en","type":"reporter","value":"Bastien Bossiroy of NCIA"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 4.8"}],"cvssRationale":"AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special conditions required; storing a crafted value and viewing the graph is straightforward. AT:N: no manipulation of the attack target needed. PR:L: attacker needs a low-privilege authenticated MISP account to create/modify an event graph. UI:P: the victim passively triggers the XSS by viewing the event graph preview (hovering a button), a normal workflow action. VC/VI/VA:N: the MISP server itself is not compromised; the impact is in the victim's browser. SC:H: the attacker can read cookies, tokens, and data in the victim's session. SI:H: the attacker can perform authenticated actions as the victim. SA:N: no availability impact on the victim's system.","fixSummary":"The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.","generatedAt":"2026-09-30T11:21:27.655462Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":9,"assumptionCount":5,"confidence":"high","model":"qwen3.8:27b","score":6}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"0ecb893de30056bc3f9609fcb8de43d60b1cedd6a1eea7d6aa53ef6d351d642a","patchSummary":"In app/Model/EventGraph.php, a new validation rule is added for the preview_img field requiring it to match the regex /^data:image\\/png;base64,[A-Za-z0-9+\\/]*={0,2}$/ (allowing empty). In app/webroot/js/event-graph.js, two occurrences of string-concatenated img tag construction (return '<img ... src=\"' + value + '\" />') are replaced with jQuery DOM construction using $('<img ...>').prop('src', value), which sets the attribute safely without HTML parsing.","patchTruncated":false,"patches":[{"commit":"92c7ccc4398a64e61699bd79fb4010703616fc59","patchSha256":"0ecb893de30056bc3f9609fcb8de43d60b1cedd6a1eea7d6aa53ef6d351d642a","source":"https://github.com/MISP/MISP/commit/92c7ccc43.patch","sourceUrl":"https://github.com/MISP/MISP/commit/92c7ccc43.patch","subject":"fix: [security] Validate the event graph preview and stop"}],"source":"https://github.com/MISP/MISP/commit/92c7ccc43.patch","subject":"fix: [security] Validate the event graph preview and stop","tagVersionBoundary":{"commits_after_fix":43,"repository":"https://github.com/MISP/MISP","tag":"v2.5.48","version":"2.5.48","version_type":"semver"},"weaknessRationale":[{"cweId":"CWE-79","rationale":"The stored preview_img value was rendered into an HTML attribute via string concatenation without sufficient neutralization, enabling script injection in the victim's browser. This is a textbook stored XSS."},{"cweId":"CWE-20","rationale":"The server accepted and persisted the preview_img field without any format validation, allowing arbitrary content to be stored and later rendered. The fix adds a strict regex validation rule."}]}}},"recordType":"advisory","vulnId":"GCVE-1-2026-20294"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-30T12:44:13.205587Z","id":"CVE-2026-103321","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-30T12:44:22.064Z"}}]}}