CVE-2026-81820

Source
https://cve.org/CVERecord?id=CVE-2026-81820
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81820.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81820
Published
2026-08-27T13:25:08Z
Modified
2026-08-30T03:30:52Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Flowintel HTML Injection in MISP Case History Timeline via Crafted Object Attributes
Details

Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as:

object UUID;

object name;

attribute value;

attribute type;

comment;

first/last seen values;

IDS flag.

Those values were concatenated directly into HTML strings before rendering. The upstream commit explicitly states that DOMPurify removed XSS vectors but still allowed other HTML elements, such as forms, through.

The fix replaces direct string interpolation with DOM construction via document.createElement() and assigns all attacker-controlled values using textContent. The headline is similarly converted to escaped HTML through a temporary element.

Version impacted =>3.3.0

Database specific
{
    "cna_assigner": "CIRCL",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81820.json"
}
References

Affected packages

Git / github.com/flowintel/flowintel

Affected ranges

Type
GIT
Repo
https://github.com/flowintel/flowintel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.3.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.0.1
0.1.0
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
1.*
1.0.0
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.6.1
1.6.2
2.*
2.0.0
2.1.0
2.1.1
2.2.1
2.3.0
3.*
3.0.0
3.1.0
3.2.0
3.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81820.json"