CVE-2026-103664
Last modified
CVE-2026-103664 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement. An attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context.
Description
MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement. An attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim. Preconditions: - The victim must be authenticated to MISP and access the analyst data view for an attribute or object. - The attacker must supply a malicious seed value in the URL path. Impact: - Execution of arbitrary JavaScript in the victim's browser session. - Potential theft of session credentials or sensitive data visible in the page. - Manipulation of the analyst data interface. Affected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-103664?
How severe is CVE-2026-103664?
How do I fix CVE-2026-103664?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-103641A flaw was found in GEGL. The Radiance HDR loader reads past…5.5
- CVE-2026-103651MISP contains a vulnerability in its one-time password (OTP)…7.6
- CVE-2026-103655MISP contains a vulnerability in its two-factor authenticati…9.3
- CVE-2026-103656Rejected reason: this is rejected
- CVE-2026-103659MISP contains an authorization bypass in the event flattenin…7.1
- CVE-2026-103662MISP contains a reflected cross-site scripting (XSS) vulnera…5.1
- CVE-2026-103678A flaw was found in tnef. An attacker can exploit this vulne…5.4
- CVE-2026-103679A flaw was found in tnef. A remote attacker could exploit th…6.5
- CVE-2026-103680A flaw was found in tnef. A heap-based buffer overflow can o…3.1
- CVE-2026-103686A flaw has been found in rhukster dom-sanitizer up to 1.0.15…3.5
- CVE-2026-103687A vulnerability has been found in rhukster dom-sanitizer up …7.3
- CVE-2026-103690A flaw has been found in itsourcecode Leave Management Syste…6.3
Are you affected by CVE-2026-103664?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
