CVE-2026-103662

EUVD-2026-90577
MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).

The affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator's browser session.

Preconditions:

- The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.

- The victim must be an authenticated site administrator.

- The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).

Security impact:

- Execution of arbitrary client-side script in the context of the administrator's browser.

- Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.

- Potential for performing privileged actions on behalf of the administrator within the MISP interface.

Affected versions: <2.5.48.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CIRCLCNA
5.1 MEDIUM
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
misp-projectmisp
𝑥
< 2.5.48
CNA