{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-104907","assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","state":"PUBLISHED","assignerShortName":"CIRCL","dateReserved":"2026-10-02T15:51:32.541Z","datePublished":"2026-10-02T15:51:34.565Z","dateUpdated":"2026-10-02T16:18:12.403Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"],"modules":["Servers/preview_event"],"product":"MISP","programFiles":["app/View/Servers/preview_event.ctp"],"repo":"https://github.com/MISP/MISP","vendor":"MISP","versions":[{"lessThan":"2.5.48","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.</p><p>Preconditions:</p><p>- A linked/remote MISP server is configured and connected to the local instance.</p><p>- The linked server supplies a crafted tag ID in an event.</p><p>- An authenticated user views the event preview and interacts with the affected tag element.</p><p>Impact:</p><p>- Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.</p><p>Affected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).</p>"}],"value":"MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.\n\nPreconditions:\n\n- A linked/remote MISP server is configured and connected to the local instance.\n\n- The linked server supplies a crafted tag ID in an event.\n\n- An authenticated user views the event preview and interacts with the affected tag element.\n\nImpact:\n\n- Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.\n\nAffected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed)."}],"impacts":[{"capecId":"CAPEC-1","descriptions":[{"lang":"en","value":"CAPEC-1 Cross Site Scripting"}]},{"capecId":"CAPEC-126","descriptions":[{"lang":"en","value":"CAPEC-126 Exploiting Incorrectly Handled Special/Control Characters"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":4.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"format":"SSVC","other":{"content":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-02T15:50:34Z","version":"2.0.3"},"type":"SSVC"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Cross-site Scripting (XSS)","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-116","description":"CWE-116 Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL","dateUpdated":"2026-10-02T15:51:34.565Z"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/70ad174dd"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.</p>"}],"value":"The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters."}],"title":"MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"full","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["The affected version boundary is inferred from the tag v2.5.48 with 28 commits after the fix; the exact first affected version is not stated in the patch.","The attacker is assumed to be a linked/remote MISP server that can control tag IDs in events shared with the local instance; the exact trust model and authentication for linked servers is not detailed in the patch.","CAPEC-126 is included as a supplementary mapping; the primary and most defensible mapping is CAPEC-1 (Cross Site Scripting).","The CVSS PR:L assumes that being a linked server requires some form of authenticated or trusted relationship, but the exact privilege level is not specified in the patch.","The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is listed as a tool credit, not a human remediation developer.","The impact scope (SC/SI) is assessed conservatively; the actual XSS payload capability depends on the browser context and same-origin policy, which are not fully specified."],"capecRationale":[{"capecId":"CAPEC-1","rationale":"The vulnerability is a reflected XSS where attacker-controlled data (a tag ID from a linked server) is injected into an inline JavaScript event handler without proper context-aware encoding. CAPEC-1 is the closest general match. The specific sub-technique is injection into a JavaScript string literal within an HTML attribute, which is not separately enumerated in CAPEC."},{"capecId":"CAPEC-126","rationale":"The attacker exploits the fact that the single-quote character (or similar) is not properly handled when the tag ID is placed inside a JavaScript string within an HTML attribute. The HTML escaping does not account for the JavaScript string delimiter. This CAPEC captures the character-handling aspect of the flaw. Uncertainty: CAPEC-1 is more directly about XSS; CAPEC-126 is included as a supplementary mapping for the encoding mismatch."}],"commit":"70ad174ddd438887687d40fc1e2e4e8b322a179e","confidence":"medium","credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"}],"cvssRationale":"AV:N - the attack originates from a remote linked server over the network. AC:L - the injection is straightforward (embed a quote in a tag ID). AT:N - no special timing or race conditions required. PR:L - the attacker must be a configured linked server, which requires some level of trust/access but not full admin. UI:A - the victim must actively view the event preview and interact with the tag element. VC/VI/VA:N - the MISP server itself is not compromised; the impact is in the victim's browser. SC:N - no meaningful confidentiality impact on the subsequent component is guaranteed. SI:L - the injected script can perform limited actions (redirect, read page data, submit forms) in the user's session. SA:N - no availability impact on the subsequent component.","fixSummary":"The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.","generatedAt":"2026-10-02T15:50:34.593118Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":11,"assumptionCount":6,"confidence":"medium","model":"qwen3.8:27b","score":6}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"048909e6f2d91cc9e6f920e8416edc5f9f44410eba1becc15373378f46a221de","patchSummary":"In app/View/Servers/preview_event.ctp, the expression h($tag['id']) inside the onclick attribute's JavaScript string was replaced with (int)$tag['id']. This changes the output from an HTML-escaped string to a strictly integer value, preventing any non-numeric characters from being injected into the inline script context.","patchTruncated":false,"patches":[{"commit":"70ad174ddd438887687d40fc1e2e4e8b322a179e","date":"Thu, 24 Sep 2026 23:53:31 +0200","patchSha256":"048909e6f2d91cc9e6f920e8416edc5f9f44410eba1becc15373378f46a221de","source":"https://github.com/MISP/MISP/commit/70ad174dd.patch","sourceUrl":"https://github.com/MISP/MISP/commit/70ad174dd.patch","subject":"fix: [security] Cast the remote tag id in the event preview"}],"source":"https://github.com/MISP/MISP/commit/70ad174dd.patch","ssvc":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-02T15:50:34Z","version":"2.0.3"},"subject":"fix: [security] Cast the remote tag id in the event preview","tagVersionBoundary":{"commits_after_fix":28,"repository":"https://github.com/MISP/MISP","tag":"v2.5.48","version":"2.5.48","version_type":"semver"},"weaknessRationale":[{"cweId":"CWE-79","rationale":"The tag ID is embedded in an inline JavaScript onclick handler where HTML escaping (h()) does not neutralize JavaScript string breakout characters. This is a classic case of improper output encoding for a JavaScript context, resulting in reflected XSS."},{"cweId":"CWE-116","rationale":"The root cause is using HTML entity encoding (h()) in a context that requires JavaScript string escaping. The encoding mechanism is inappropriate for the output context, which is a sub-category of the XSS issue."}]}},"bcp-05-x-03":{"x_timeline":{"events":[{"description":"Corrective change authored (70ad174ddd438887687d40fc1e2e4e8b322a179e): fix: [security] Cast the remote tag id in the event preview","id":"evt-fix-developed-1","references":["https://github.com/MISP/MISP/commit/70ad174dd.patch"],"timestamp":"2026-09-24T21:53:31Z","type":"fix-developed"}]}}},"recordType":"advisory","vulnId":"GCVE-1-2026-20154"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-02T16:17:59.477633Z","id":"CVE-2026-104907","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-02T16:18:12.403Z"}}]}}