{"api_version":"1","generated_at":"2026-10-02T21:15:51+00:00","cve":"CVE-2026-104907","urls":{"html":"https://cve.report/CVE-2026-104907","api":"https://cve.report/api/cve/CVE-2026-104907.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-104907","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-104907"},"summary":{"title":"MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler","description":"MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.\n\nPreconditions:\n\n- A linked/remote MISP server is configured and connected to the local instance.\n\n- The linked server supplies a crafted tag ID in an event.\n\n- An authenticated user views the event preview and interacts with the affected tag element.\n\nImpact:\n\n- Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.\n\nAffected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).","state":"PUBLISHED","assigner":"CIRCL","published_at":"2026-10-02 16:16:48","updated_at":"2026-10-02 17:17:04"},"problem_types":["CWE-79","CWE-116","CWE-79 CWE-79 Cross-site Scripting (XSS)","CWE-116 CWE-116 Improper Encoding or Escaping of Output"],"metrics":[{"version":"4.0","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","score":"4.8","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"4.8","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":4.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/MISP/MISP/commit/70ad174dd","name":"https://github.com/MISP/MISP/commit/70ad174dd","refsource":"5a6e4751-2f3f-4070-9419-94fb35b644e8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-104907","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104907","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"MISP","product":"MISP","version":"affected 2.5.48 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Jeroen Pinoy","lang":"en"},{"source":"CNA","value":"iglocska","lang":"en"},{"source":"CNA","value":"Claude Opus 5.5 (1M context)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-104907","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-02T16:17:59.477633Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-02T16:18:12.403Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"],"modules":["Servers/preview_event"],"product":"MISP","programFiles":["app/View/Servers/preview_event.ctp"],"repo":"https://github.com/MISP/MISP","vendor":"MISP","versions":[{"lessThan":"2.5.48","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.</p><p>Preconditions:</p><p>- A linked/remote MISP server is configured and connected to the local instance.</p><p>- The linked server supplies a crafted tag ID in an event.</p><p>- An authenticated user views the event preview and interacts with the affected tag element.</p><p>Impact:</p><p>- Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.</p><p>Affected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).</p>"}],"value":"MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.\n\nPreconditions:\n\n- A linked/remote MISP server is configured and connected to the local instance.\n\n- The linked server supplies a crafted tag ID in an event.\n\n- An authenticated user views the event preview and interacts with the affected tag element.\n\nImpact:\n\n- Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.\n\nAffected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed)."}],"impacts":[{"capecId":"CAPEC-1","descriptions":[{"lang":"en","value":"CAPEC-1 Cross Site Scripting"}]},{"capecId":"CAPEC-126","descriptions":[{"lang":"en","value":"CAPEC-126 Exploiting Incorrectly Handled Special/Control Characters"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":4.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"format":"SSVC","other":{"content":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-02T15:50:34Z","version":"2.0.3"},"type":"SSVC"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Cross-site Scripting (XSS)","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-116","description":"CWE-116 Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-02T15:51:34.565Z","orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/70ad174dd"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.</p>"}],"value":"The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters."}],"title":"MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"full","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["The affected version boundary is inferred from the tag v2.5.48 with 28 commits after the fix; the exact first affected version is not stated in the patch.","The attacker is assumed to be a linked/remote MISP server that can control tag IDs in events shared with the local instance; the exact trust model and authentication for linked servers is not detailed in the patch.","CAPEC-126 is included as a supplementary mapping; the primary and most defensible mapping is CAPEC-1 (Cross Site Scripting).","The CVSS PR:L assumes that being a linked server requires some form of authenticated or trusted relationship, but the exact privilege level is not specified in the patch.","The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is listed as a tool credit, not a human remediation developer.","The impact scope (SC/SI) is assessed conservatively; the actual XSS payload capability depends on the browser context and same-origin policy, which are not fully specified."],"capecRationale":[{"capecId":"CAPEC-1","rationale":"The vulnerability is a reflected XSS where attacker-controlled data (a tag ID from a linked server) is injected into an inline JavaScript event handler without proper context-aware encoding. CAPEC-1 is the closest general match. The specific sub-technique is injection into a JavaScript string literal within an HTML attribute, which is not separately enumerated in CAPEC."},{"capecId":"CAPEC-126","rationale":"The attacker exploits the fact that the single-quote character (or similar) is not properly handled when the tag ID is placed inside a JavaScript string within an HTML attribute. The HTML escaping does not account for the JavaScript string delimiter. This CAPEC captures the character-handling aspect of the flaw. Uncertainty: CAPEC-1 is more directly about XSS; CAPEC-126 is included as a supplementary mapping for the encoding mismatch."}],"commit":"70ad174ddd438887687d40fc1e2e4e8b322a179e","confidence":"medium","credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"}],"cvssRationale":"AV:N - the attack originates from a remote linked server over the network. AC:L - the injection is straightforward (embed a quote in a tag ID). AT:N - no special timing or race conditions required. PR:L - the attacker must be a configured linked server, which requires some level of trust/access but not full admin. UI:A - the victim must actively view the event preview and interact with the tag element. VC/VI/VA:N - the MISP server itself is not compromised; the impact is in the victim's browser. SC:N - no meaningful confidentiality impact on the subsequent component is guaranteed. SI:L - the injected script can perform limited actions (redirect, read page data, submit forms) in the user's session. SA:N - no availability impact on the subsequent component.","fixSummary":"The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.","generatedAt":"2026-10-02T15:50:34.593118Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":11,"assumptionCount":6,"confidence":"medium","model":"qwen3.8:27b","score":6}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"048909e6f2d91cc9e6f920e8416edc5f9f44410eba1becc15373378f46a221de","patchSummary":"In app/View/Servers/preview_event.ctp, the expression h($tag['id']) inside the onclick attribute's JavaScript string was replaced with (int)$tag['id']. This changes the output from an HTML-escaped string to a strictly integer value, preventing any non-numeric characters from being injected into the inline script context.","patchTruncated":false,"patches":[{"commit":"70ad174ddd438887687d40fc1e2e4e8b322a179e","date":"Thu, 24 Sep 2026 23:53:31 +0200","patchSha256":"048909e6f2d91cc9e6f920e8416edc5f9f44410eba1becc15373378f46a221de","source":"https://github.com/MISP/MISP/commit/70ad174dd.patch","sourceUrl":"https://github.com/MISP/MISP/commit/70ad174dd.patch","subject":"fix: [security] Cast the remote tag id in the event preview"}],"source":"https://github.com/MISP/MISP/commit/70ad174dd.patch","ssvc":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-02T15:50:34Z","version":"2.0.3"},"subject":"fix: [security] Cast the remote tag id in the event preview","tagVersionBoundary":{"commits_after_fix":28,"repository":"https://github.com/MISP/MISP","tag":"v2.5.48","version":"2.5.48","version_type":"semver"},"weaknessRationale":[{"cweId":"CWE-79","rationale":"The tag ID is embedded in an inline JavaScript onclick handler where HTML escaping (h()) does not neutralize JavaScript string breakout characters. This is a classic case of improper output encoding for a JavaScript context, resulting in reflected XSS."},{"cweId":"CWE-116","rationale":"The root cause is using HTML entity encoding (h()) in a context that requires JavaScript string escaping. The encoding mechanism is inappropriate for the output context, which is a sub-category of the XSS issue."}]}},"bcp-05-x-03":{"x_timeline":{"events":[{"description":"Corrective change authored (70ad174ddd438887687d40fc1e2e4e8b322a179e): fix: [security] Cast the remote tag id in the event preview","id":"evt-fix-developed-1","references":["https://github.com/MISP/MISP/commit/70ad174dd.patch"],"timestamp":"2026-09-24T21:53:31Z","type":"fix-developed"}]}}},"recordType":"advisory","vulnId":"GCVE-1-2026-20154"}]}},"cveMetadata":{"assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","assignerShortName":"CIRCL","cveId":"CVE-2026-104907","datePublished":"2026-10-02T15:51:34.565Z","dateReserved":"2026-10-02T15:51:32.541Z","dateUpdated":"2026-10-02T16:18:12.403Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-02 16:16:48","lastModifiedDate":"2026-10-02 17:17:04","problem_types":["CWE-79","CWE-116","CWE-79 CWE-79 Cross-site Scripting (XSS)","CWE-116 CWE-116 Improper Encoding or Escaping of Output"],"metrics":{"cvssMetricV40":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","ssvcData":{"timestamp":"2026-10-02T15:50:34Z","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"Supplier","version":"2.0.3"}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-02T16:17:59.477633Z","id":"CVE-2026-104907","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"104907","Ordinal":"1","Title":"MISP: JavaScript Injection via Remote Tag ID in Event Preview In","CVE":"CVE-2026-104907","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"104907","Ordinal":"1","NoteData":"MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.\n\nPreconditions:\n\n- A linked/remote MISP server is configured and connected to the local instance.\n\n- The linked server supplies a crafted tag ID in an event.\n\n- An authenticated user views the event preview and interacts with the affected tag element.\n\nImpact:\n\n- Arbitrary JavaScript execution in the context of the viewing user's browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.\n\nAffected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).","Type":"Description","Title":"MISP: JavaScript Injection via Remote Tag ID in Event Preview In"}]}}}