SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85227

MEDIUM · CVSS 6.1 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the MISP platform, specifically in the event attribute filtering query builder, where user-controlled URL parameters are improperly handled, allowing for reflected Cross-Site Scripting (XSS) attacks. An attacker can exploit this by tricking an authenticated user into clicking a malicious link, potentially executing arbitrary JavaScript within the user's session and compromising sensitive data or actions. Organizations using MISP should prioritize this vulnerability to protect their users and data integrity from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85227
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%
Java

Original NVD Description

MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the query-builder rules without HTML escaping before being serialized as JSON and embedded inside a <script> element. Because JsonTool::encode() uses JSON_UNESCAPED_SLASHES, an attacker-controlled value containing a closing </script> sequence could terminate the surrounding script element and inject arbitrary HTML or JavaScript. For example, a specially crafted viewEventAttributes URL could contain malicious content in one of the affected filter parameters. An attacker could exploit the vulnerability by convincing an authenticated MISP user to follow a crafted URL. Successful exploitation would execute attacker-controlled JavaScript in the security context of the MISP instance and with the privileges of the victim's authenticated browser session. This could allow access to information available to the victim, modification of data through authenticated requests, or other actions permitted by the victim's MISP permissions. The vulnerability is addressed by applying HTML escaping with h() to both scalar and array values before they are inserted into the DOM.

Related CVEs

Other vulnerabilities affecting the same vendor(s)