{"api_version":"1","generated_at":"2026-10-01T18:35:12+00:00","cve":"CVE-2026-103664","urls":{"html":"https://cve.report/CVE-2026-103664","api":"https://cve.report/api/cve/CVE-2026-103664.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-103664","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-103664"},"summary":{"title":"MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter","description":"MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement.\n\nAn attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim.\n\nPreconditions:\n\n- The victim must be authenticated to MISP and access the analyst data view for an attribute or object.\n\n- The attacker must supply a malicious seed value in the URL path.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim's browser session.\n\n- Potential theft of session credentials or sensitive data visible in the page.\n\n- Manipulation of the analyst data interface.\n\nAffected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).","state":"PUBLISHED","assigner":"CIRCL","published_at":"2026-10-01 09:17:08","updated_at":"2026-10-01 16:17:38"},"problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":[{"version":"4.0","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","score":"4.8","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"4.8","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":4.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/MISP/MISP/commit/58925dbf0","name":"https://github.com/MISP/MISP/commit/58925dbf0","refsource":"5a6e4751-2f3f-4070-9419-94fb35b644e8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-103664","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103664","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"MISP","product":"MISP","version":"affected 2.5.48 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Jeroen Pinoy","lang":"en"},{"source":"CNA","value":"iglocska","lang":"en"},{"source":"CNA","value":"Claude Opus 5.5 (1M context)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-103664","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-01T15:06:14.886463Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-01T15:06:25.374Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"],"modules":["AttributesController::viewAnalystData","ObjectsController::viewAnalystData","Analyst_data view templates"],"product":"MISP","programFiles":["app/Controller/AttributesController.php","app/Controller/ObjectsController.php","app/View/Elements/genericElements/Analyst_data/generic_simple.ctp","app/View/Elements/genericElements/Analyst_data/thread.ctp"],"repo":"https://github.com/MISP/MISP","vendor":"MISP","versions":[{"lessThan":"2.5.48","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement.</p><p>An attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim.</p><p>Preconditions:</p><p>- The victim must be authenticated to MISP and access the analyst data view for an attribute or object.</p><p>- The attacker must supply a malicious seed value in the URL path.</p><p>Impact:</p><p>- Execution of arbitrary JavaScript in the victim's browser session.</p><p>- Potential theft of session credentials or sensitive data visible in the page.</p><p>- Manipulation of the analyst data interface.</p><p>Affected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).</p>"}],"value":"MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement.\n\nAn attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim.\n\nPreconditions:\n\n- The victim must be authenticated to MISP and access the analyst data view for an attribute or object.\n\n- The attacker must supply a malicious seed value in the URL path.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim's browser session.\n\n- Potential theft of session credentials or sensitive data visible in the page.\n\n- Manipulation of the analyst data interface.\n\nAffected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48)."}],"impacts":[{"capecId":"CAPEC-1","descriptions":[{"lang":"en","value":"CAPEC-1 XSS - Reflected"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":4.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"format":"SSVC","other":{"content":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-01T08:49:54Z","version":"2.0.3"},"type":"SSVC"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-01T08:55:51.589Z","orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/58925dbf0"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.</p>"}],"value":"The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector."}],"title":"MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"full","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["MISP requires user authentication to access the analyst data views; PR:L assumes a low-privilege authenticated account is sufficient for the attacker to craft or deliver the malicious URL.","The exact fixed version number is not stated in the patch; the fix commit is 32 commits after the v2.5.48 tag, so the fixed version is presumed to be a release after 2.5.48.","The UI:A rating assumes the victim must click a link or navigate to the crafted URL; if the seed could be injected via a different vector requiring no user interaction, UI could be None.","CAPEC-1 (Reflected XSS) is selected as the closest match; the injection occurs server-side into the HTML response, distinguishing it from DOM-based XSS (CAPEC-64)."],"capecRationale":[{"capecId":"CAPEC-1","rationale":"The attacker supplies a malicious value in a URL parameter (seed), which the server reflects unmodified into inline JavaScript in the HTTP response. The victim's browser executes the injected script. This matches the reflected XSS pattern precisely. No uncertainty in this mapping."}],"commit":"58925dbf01c2fe5dfe9b2f61a421f6463f66ca56","confidence":"high","credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"}],"cvssRationale":"AV:N - exploitable over the network via a crafted URL. AC:L - no race conditions or special conditions; a simple URL with a malicious seed suffices. AT:N - no prior manipulation of the target system needed. PR:L - MISP is an authenticated platform; the attacker needs at least a low-privilege account or must target an authenticated user. UI:A - the victim must actively navigate to the crafted URL. VC/VI/VA:N - the server-side confidentiality, integrity, and availability are not directly impacted. SC:L - the victim's browser session data (cookies, tokens) can be read. SI:L - the victim's page content can be modified. SA:N - no impact on security authority.","fixSummary":"The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.","generatedAt":"2026-10-01T08:49:54.035056Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":11,"assumptionCount":4,"confidence":"high","model":"qwen3.8:27b","score":9}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"7e384946a0fb4f1d43dee43a5374cabf2e70c31add4a6d2e4fa845cdc5ee5b37","patchSummary":"In AttributesController.php and ObjectsController.php, the seed value set for the view is now cast to an integer with a fallback to a random integer if the cast yields zero. In the two analyst data view templates (generic_simple.ctp and thread.ctp), the seed variable is similarly cast to an integer before use in inline script, replacing the previous logic that only checked for emptiness without type enforcement.","patchTruncated":false,"patches":[{"commit":"58925dbf01c2fe5dfe9b2f61a421f6463f66ca56","date":"Thu, 24 Sep 2026 18:06:24 +0200","patchSha256":"7e384946a0fb4f1d43dee43a5374cabf2e70c31add4a6d2e4fa845cdc5ee5b37","source":"https://github.com/MISP/MISP/commit/58925dbf0.patch","sourceUrl":"https://github.com/MISP/MISP/commit/58925dbf0.patch","subject":"fix: [security] Cast the analyst data seed to an integer"}],"source":"https://github.com/MISP/MISP/commit/58925dbf0.patch","ssvc":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-01T08:49:54Z","version":"2.0.3"},"subject":"fix: [security] Cast the analyst data seed to an integer","tagVersionBoundary":{"commits_after_fix":32,"repository":"https://github.com/MISP/MISP","tag":"v2.5.48","version":"2.5.48","version_type":"semver"},"weaknessRationale":[{"cweId":"CWE-79","rationale":"The user-supplied seed parameter was reflected into inline JavaScript in the HTML response without sanitization or type coercion, allowing script injection. This is a textbook reflected XSS."}]}},"bcp-05-x-03":{"x_timeline":{"events":[{"description":"Corrective change authored (58925dbf01c2fe5dfe9b2f61a421f6463f66ca56): fix: [security] Cast the analyst data seed to an integer","id":"evt-fix-developed-1","references":["https://github.com/MISP/MISP/commit/58925dbf0.patch"],"timestamp":"2026-09-24T16:06:24Z","type":"fix-developed"}]}}},"recordType":"advisory","vulnId":"GCVE-1-2026-20241"}]}},"cveMetadata":{"assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","assignerShortName":"CIRCL","cveId":"CVE-2026-103664","datePublished":"2026-10-01T08:55:51.589Z","dateReserved":"2026-10-01T08:55:49.992Z","dateUpdated":"2026-10-01T15:06:25.374Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-01 09:17:08","lastModifiedDate":"2026-10-01 16:17:38","problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":{"cvssMetricV40":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","ssvcData":{"timestamp":"2026-10-01T08:49:54Z","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"Supplier","version":"2.0.3"}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-01T15:06:14.886463Z","id":"CVE-2026-103664","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"103664","Ordinal":"1","Title":"MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data","CVE":"CVE-2026-103664","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"103664","Ordinal":"1","NoteData":"MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement.\n\nAn attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim.\n\nPreconditions:\n\n- The victim must be authenticated to MISP and access the analyst data view for an attribute or object.\n\n- The attacker must supply a malicious seed value in the URL path.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim's browser session.\n\n- Potential theft of session credentials or sensitive data visible in the page.\n\n- Manipulation of the analyst data interface.\n\nAffected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).","Type":"Description","Title":"MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data"}]}}}