CVE-2026-103389

Source
https://cve.org/CVERecord?id=CVE-2026-103389
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103389.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103389
Published
2026-09-30T14:25:59Z
Modified
2026-10-04T02:46:16Z
Severity
  • 6.2 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph
Details

MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.

A user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.

Impact:

  • Arbitrary script execution in the context of the victim's MISP session

  • Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim

  • Affects both the default and Overmind UI themes

Affected versions: <2.5.48

Database specific
{
    "cna_assigner":  "CIRCL",
    "cwe_ids":  [
        "CWE-20",
        "CWE-79"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103389.json"
}
References

Affected packages

Git / github.com/misp/misp

Affected ranges

Type
GIT
Repo
https://github.com/misp/misp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.5.48"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103389.json"