Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox.
The commit explains that SVG files are XML documents rather than passive bitmap images. While scripts inside SVG do not execute when the SVG is rendered through a normal , they can execute when the SVG is navigated to directly or embedded as a document. In that case, malicious
{
"cna_assigner": "CIRCL",
"cwe_ids": [
"CWE-693",
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90957.json"
}