Action not permitted
Modal body text goes here.
Modal Title
Modal Body
WID-SEC-W-2026-3689
Vulnerability from csaf_certbund - Published: 2026-09-30 22:00 - Updated: 2026-09-30 22:00| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Open Source MISP <2.5.48
Open Source / MISP
|
<2.5.48 |
{
"document": {
"aggregate_severity": {
"text": "hoch"
},
"category": "csaf_base",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "de-DE",
"notes": [
{
"category": "legal_disclaimer",
"text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen."
},
{
"category": "description",
"text": "MISP ist eine Open-Source-Plattform f\u00fcr den Informationsaustausch \u00fcber Bedrohungen.",
"title": "Produktbeschreibung"
},
{
"category": "summary",
"text": "Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in MISP ausnutzen, um seine Berechtigungen bis auf \u201eSite-Administrator\u201d-Ebene zu erweitern, Sicherheitsma\u00dfnahmen zu umgehen, Daten zu manipulieren oder offenzulegen sowie Cross-Site-Scripting-Angriffe durchzuf\u00fchren.",
"title": "Angriff"
},
{
"category": "general",
"text": "- Linux\n- MacOS X\n- Windows",
"title": "Betroffene Betriebssysteme"
}
],
"publisher": {
"category": "other",
"contact_details": "csaf-provider@cert-bund.de",
"name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"namespace": "https://www.bsi.bund.de"
},
"references": [
{
"category": "self",
"summary": "WID-SEC-W-2026-3689 - CSAF Version",
"url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3689.json"
},
{
"category": "self",
"summary": "WID-SEC-2026-3689 - Portal Version",
"url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3689"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-30",
"url": "https://github.com/advisories/GHSA-J2MF-Q9C3-GWXW"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-30",
"url": "https://github.com/advisories/GHSA-52C6-QG88-JH84"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-30",
"url": "https://github.com/advisories/GHSA-VPMP-H7JX-6GFX"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-30",
"url": "https://github.com/advisories/GHSA-W4MV-4X7W-VPVV"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-30",
"url": "https://github.com/advisories/GHSA-CCJM-JPCQ-P5HF"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-09-30",
"url": "https://github.com/advisories/GHSA-58W8-2929-FQHF"
}
],
"source_lang": "en-US",
"title": "MISP: Mehrere Schwachstellen",
"tracking": {
"current_release_date": "2026-09-30T22:00:00.000+00:00",
"generator": {
"date": "2026-10-01T11:11:30.046+00:00",
"engine": {
"name": "BSI-WID",
"version": "1.6.0"
}
},
"id": "WID-SEC-W-2026-3689",
"initial_release_date": "2026-09-30T22:00:00.000+00:00",
"revision_history": [
{
"date": "2026-09-30T22:00:00.000+00:00",
"number": "1",
"summary": "Initiale Fassung"
}
],
"status": "final",
"version": "1"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2.5.48",
"product": {
"name": "Open Source MISP \u003c2.5.48",
"product_id": "T060493"
}
},
{
"category": "product_version",
"name": "2.5.48",
"product": {
"name": "Open Source MISP 2.5.48",
"product_id": "T060493-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:misp:misp:2.5.48"
}
}
}
],
"category": "product_name",
"name": "MISP"
}
],
"category": "vendor",
"name": "Open Source"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-103235",
"product_status": {
"known_affected": [
"T060493"
]
},
"release_date": "2026-09-30T22:00:00.000+00:00",
"title": "CVE-2026-103235"
},
{
"cve": "CVE-2026-103237",
"product_status": {
"known_affected": [
"T060493"
]
},
"release_date": "2026-09-30T22:00:00.000+00:00",
"title": "CVE-2026-103237"
},
{
"cve": "CVE-2026-103239",
"product_status": {
"known_affected": [
"T060493"
]
},
"release_date": "2026-09-30T22:00:00.000+00:00",
"title": "CVE-2026-103239"
},
{
"cve": "CVE-2026-103321",
"product_status": {
"known_affected": [
"T060493"
]
},
"release_date": "2026-09-30T22:00:00.000+00:00",
"title": "CVE-2026-103321"
},
{
"cve": "CVE-2026-103388",
"product_status": {
"known_affected": [
"T060493"
]
},
"release_date": "2026-09-30T22:00:00.000+00:00",
"title": "CVE-2026-103388"
},
{
"cve": "CVE-2026-103389",
"product_status": {
"known_affected": [
"T060493"
]
},
"release_date": "2026-09-30T22:00:00.000+00:00",
"title": "CVE-2026-103389"
}
]
}
CVE-2026-103235 (GCVE-0-2026-103235)
Vulnerability from cvelistv5 – Published: 2026-09-30 09:09 – Updated: 2026-09-30 14:32| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/d1f5684f9 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 07:37 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/d1f5684f9.patch
f478751165e6… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
d1f5684f9a19
|
fix: [security] Delegation requests stay bound to the event | f478751165e6… |
Fix summary
The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.
Patch summary
In EventDelegationsController::delegateEvent(), the code previously saved $this->request->data['EventDelegation'] directly after setting a few fields. The fix replaces this with an explicit allow-list array containing only event_id (from the authorized URL event), requester_org_id (from the session), org_id (resolved from submitted UUID), message, distribution, and sharing_group_id. The primary key id is never included. A regression test class DelegationRequestRetargeting was added to verify that injecting a nested EventDelegation with a foreign id and event_id does not grant read access to the victim event.
CVSS rationale
Network vector: MISP is a web application accessible over HTTP. Low complexity: a single crafted POST request suffices. No attack target manipulation. Low privileges: requires an authenticated user with perm_delegate. No user interaction: read access is granted immediately upon creating the retargeted delegation. High confidentiality: grants read access to any event on the instance. High integrity: overwrites existing delegation records and can transfer event ownership. No availability impact without victim acceptance. Scope change (SC:H, SI:H): the vulnerability crosses organisational boundaries, affecting data owned by other organisations. No sub-system availability impact.
Weakness rationale
- CWE-915 The application persisted the entire user-submitted record including fields (id, event_id) that should not be attacker-controllable, allowing mass assignment of sensitive fields to retarget the delegation.
- CWE-639 The authorization check validated only the event in the URL, but the attacker-supplied primary key or event_id in the payload redirected the operation to a different record, bypassing the intended authorization boundary.
Attack pattern rationale
- CAPEC-12 The attacker manipulates hidden or additional fields in a form/API request (injecting id and event_id into the EventDelegation payload) to modify data beyond what the application intended to accept. This is the canonical mass assignment pattern: the server processes user-supplied fields it should have ignored. The mapping is direct and well-supported by the patch evidence.
Assumptions to verify
- The affected version boundary (< 2.5.48) is inferred from the tag_version_boundary metadata showing v2.5.48 as the nearest tag with 22 commits after the fix; the exact last affected release is not explicitly stated in the patch.
- PR:L assumes the attacker needs only the perm_delegate permission, which is a non-admin role; the exact role configuration may vary by deployment.
- VA:N assumes the availability impact (deletion of the original event) requires victim acceptance and is therefore not a direct availability impact of the vulnerability itself.
- The CAPEC-12 mapping is the closest standard pattern; the vulnerability also has IDOR characteristics (CWE-639) but CAPEC-12 best captures the mass-assignment mechanism demonstrated in the patch.
- The MISP.delegation server setting must be enabled for the vulnerability to be exploitable; this is a deployment configuration assumption.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103235",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:32:35.584208Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:32:45.581Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"EventDelegationsController"
],
"product": "MISP",
"programFiles": [
"app/Controller/EventDelegationsController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\u003c/p\u003e\u003cp\u003eAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated user with the delegation permission (perm_delegate)\u003c/p\u003e\u003cp\u003e- The MISP.delegation server setting must be enabled\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Confidentiality: read access to any event on the instance\u003c/p\u003e\u003cp\u003e- Integrity: overwriting existing delegation records and transferring event ownership\u003c/p\u003e\u003cp\u003eAffected versions: MISP \u0026lt; 2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\n\nAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\n\nPreconditions:\n\n- An authenticated user with the delegation permission (perm_delegate)\n\n- The MISP.delegation server setting must be enabled\n\nImpact:\n\n- Confidentiality: read access to any event on the instance\n\n- Integrity: overwriting existing delegation records and transferring event ownership\n\nAffected versions: MISP \u003c 2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-12",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-12 Mass Assignment"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T09:12:56.533Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/d1f5684f9"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.\u003c/p\u003e"
}
],
"value": "The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary (\u003c 2.5.48) is inferred from the tag_version_boundary metadata showing v2.5.48 as the nearest tag with 22 commits after the fix; the exact last affected release is not explicitly stated in the patch.",
"PR:L assumes the attacker needs only the perm_delegate permission, which is a non-admin role; the exact role configuration may vary by deployment.",
"VA:N assumes the availability impact (deletion of the original event) requires victim acceptance and is therefore not a direct availability impact of the vulnerability itself.",
"The CAPEC-12 mapping is the closest standard pattern; the vulnerability also has IDOR characteristics (CWE-639) but CAPEC-12 best captures the mass-assignment mechanism demonstrated in the patch.",
"The MISP.delegation server setting must be enabled for the vulnerability to be exploitable; this is a deployment configuration assumption."
],
"capecRationale": [
{
"capecId": "CAPEC-12",
"rationale": "The attacker manipulates hidden or additional fields in a form/API request (injecting id and event_id into the EventDelegation payload) to modify data beyond what the application intended to accept. This is the canonical mass assignment pattern: the server processes user-supplied fields it should have ignored. The mapping is direct and well-supported by the patch evidence."
}
],
"commit": "d1f5684f9a193ea0a8a4f7709703011aa69d9682",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"cvssRationale": "Network vector: MISP is a web application accessible over HTTP. Low complexity: a single crafted POST request suffices. No attack target manipulation. Low privileges: requires an authenticated user with perm_delegate. No user interaction: read access is granted immediately upon creating the retargeted delegation. High confidentiality: grants read access to any event on the instance. High integrity: overwrites existing delegation records and can transfer event ownership. No availability impact without victim acceptance. Scope change (SC:H, SI:H): the vulnerability crosses organisational boundaries, affecting data owned by other organisations. No sub-system availability impact.",
"fixSummary": "The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.",
"generatedAt": "2026-09-30T07:37:05.841152Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "f478751165e658f2b26822845ec034386d8a1740527cf30863792e9521f24611",
"patchSummary": "In EventDelegationsController::delegateEvent(), the code previously saved $this-\u003erequest-\u003edata[\u0027EventDelegation\u0027] directly after setting a few fields. The fix replaces this with an explicit allow-list array containing only event_id (from the authorized URL event), requester_org_id (from the session), org_id (resolved from submitted UUID), message, distribution, and sharing_group_id. The primary key id is never included. A regression test class DelegationRequestRetargeting was added to verify that injecting a nested EventDelegation with a foreign id and event_id does not grant read access to the victim event.",
"patchTruncated": false,
"patches": [
{
"commit": "d1f5684f9a193ea0a8a4f7709703011aa69d9682",
"patchSha256": "f478751165e658f2b26822845ec034386d8a1740527cf30863792e9521f24611",
"source": "https://github.com/MISP/MISP/commit/d1f5684f9.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/d1f5684f9.patch",
"subject": "fix: [security] Delegation requests stay bound to the event"
}
],
"source": "https://github.com/MISP/MISP/commit/d1f5684f9.patch",
"subject": "fix: [security] Delegation requests stay bound to the event",
"tagVersionBoundary": {
"commits_after_fix": 22,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-915",
"rationale": "The application persisted the entire user-submitted record including fields (id, event_id) that should not be attacker-controllable, allowing mass assignment of sensitive fields to retarget the delegation."
},
{
"cweId": "CWE-639",
"rationale": "The authorization check validated only the event in the URL, but the attacker-supplied primary key or event_id in the payload redirected the operation to a different record, bypassing the intended authorization boundary."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20227"
}
],
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103235",
"datePublished": "2026-09-30T09:09:36.761Z",
"dateReserved": "2026-09-30T09:09:33.466Z",
"dateUpdated": "2026-09-30T14:32:45.581Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103237 (GCVE-0-2026-103237)
Vulnerability from cvelistv5 – Published: 2026-09-30 09:56 – Updated: 2026-09-30 17:08| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/9485ae40d | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 09:24 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/9485ae40d.patch
03af388a5ac0… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
9485ae40d334
|
fix: [security] A nested model alias key no longer selects | 03af388a5ac0… |
Fix summary
The fix introduces a defensive save() override in the base model class that refuses to persist any record where the data array simultaneously contains a nested key matching the model alias and other top-level scalar fields, logging a warning and returning false. Additionally, all code paths that sanitize and save records (free-text import, module result processing, object delta merge, attribute bulk edit, sighting capture, shadow attribute proposal, event report creation) now explicitly unset the nested alias key from the data array before calling save(), ensuring the ORM cannot be redirected to an attacker-chosen row. Controller-level request reshaping was also corrected to avoid creating self-referencing data structures.
Patch summary
Added a save() override in AppModel.php that detects and rejects ambiguous payloads containing both a nested model-alias key and outer scalars. Added unset($data[$this->alias]) calls in Event.php (free-text, module results, object attribute save), MispAttribute.php (saveAttributes, captureAttribute, editAttributeBulk), MispObject.php (deltaMerge, editObject), ShadowAttribute.php (__preCaptureMassage), and Sighting.php (captureSightings) to strip the nested alias key before save. Changed six controller files to use $this->request->data = array('Model' => $this->request->data) instead of $this->request->data['Model'] = $this->request->data, preventing self-referencing structures. Added a new regression test suite (tests/testregressions.py) with cross-tenant attack scenarios and wired it into the CI workflow.
CVSS rationale
AV:N - MISP is a network-accessible web application. AC:L - The attack requires only crafting a request with a nested alias key; no race condition or complex state is needed. AT:N - No in-transit tampering required. PR:L - An authenticated user with basic write permission (perm_add) suffices; no admin or sync role needed. UI:N - No victim interaction required. VC:N - The attacker does not gain new read access; the impact is on data they can already partially see or infer. VI:H - The attacker can overwrite, re-parent, or soft-delete rows in the same instance, causing high integrity loss to the vulnerable component's data. VA:N - Soft-delete is a state change (integrity) rather than a service disruption. SC:N - No impact on separate components' confidentiality. SI:H - The cross-tenant nature means integrity of other organizations' data (a separate security scope) is compromised. SA:N - No security mechanism is weakened.
Weakness rationale
- CWE-639 The attacker controls the row identifier (id) inside the nested alias block, which the ORM uses to select the target row. The application's authorization and sanitization (id stripping, event_id pinning) is applied to the outer record and is bypassed because the ORM binds to the inner record. This is a direct case of a user-controlled key selecting an unauthorized resource.
- CWE-20 The application fails to validate or strip the nested model-alias key from user-supplied data before passing it to the ORM. The ORM's set() method interprets this key as the record to save, contradicting the application's intent. The absence of validation on this structural aspect of the input is the root cause.
Attack pattern rationale
- CAPEC-24 The attacker tampers with the structure of request parameters by injecting a nested key matching the model alias, causing the ORM to target a different row than the application intended. The outer parameters (sanitized id, pinned event_id) are effectively ignored in favor of the attacker-controlled inner parameters. This is a structural parameter tampering attack exploiting the ORM's data-binding semantics. The mapping is the closest available CAPEC; no more specific pattern for ORM-level key injection exists in the CAPEC catalog.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48); the exact last affected release and first fixed release are not explicitly stated in the patch.
- PR:L assumes the attacker needs only a basic authenticated account with perm_add; the regression tests confirm a non-admin, non-sync role suffices, but the minimum permission set is not exhaustively enumerated in the patch.
- VA:N assumes soft-delete is treated as an integrity impact (data state change) rather than an availability impact; if the organization considers soft-deleted records as unavailable, VA could be raised to L.
- CAPEC-24 (Parameter Tampering) is the closest available pattern; the specific ORM-level key-binding manipulation does not have a dedicated CAPEC entry, so the mapping is approximate.
- The Co-Authored-By line references an AI tool (Claude Opus 5); it is listed as a tool credit, not a human remediation developer, per CVE credit role semantics.
- The commit date is 2026-09-25; the vulnerability may have existed for an unknown duration prior to reporting.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | high | 6 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103237",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T17:08:29.034418Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T17:08:51.346Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"AttributesController",
"EventReportsController",
"EventsController",
"ObjectReferencesController",
"ShadowAttributesController",
"UsersController",
"AppModel",
"Event model",
"MispAttribute model",
"MispObject model",
"ShadowAttribute model",
"Sighting model"
],
"product": "MISP",
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the flat record by stripping the primary key and pinning the event_id or object_id to the caller\u0027s context. However, the underlying ORM\u0027s set() method gives priority to a nested key whose name matches the model alias and discards the outer scalar fields.\u003c/p\u003e\u003cp\u003eAn authenticated user with basic write permissions can exploit this by embedding a nested block under the model alias key inside their request. The sanitization logic (id removal, event_id pinning) is applied to the outer record, but the ORM binds to the inner record instead, which carries an attacker-chosen id and event_id. This allows the attacker to overwrite, re-parent, or soft-delete rows belonging to other organizations or events they have no read access to.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Cross-tenant data integrity compromise (attribute values rewritten, objects re-parented to attacker events, rows soft-deleted)\u003c/p\u003e\u003cp\u003e- Affects multiple entity types: Attribute, Object, EventReport, Sighting, AttributeTag, ShadowAttribute\u003c/p\u003e\u003cp\u003e- Requires only a low-privilege authenticated account with perm_add\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the flat record by stripping the primary key and pinning the event_id or object_id to the caller\u0027s context. However, the underlying ORM\u0027s set() method gives priority to a nested key whose name matches the model alias and discards the outer scalar fields.\n\nAn authenticated user with basic write permissions can exploit this by embedding a nested block under the model alias key inside their request. The sanitization logic (id removal, event_id pinning) is applied to the outer record, but the ORM binds to the inner record instead, which carries an attacker-chosen id and event_id. This allows the attacker to overwrite, re-parent, or soft-delete rows belonging to other organizations or events they have no read access to.\n\nImpact:\n\n- Cross-tenant data integrity compromise (attribute values rewritten, objects re-parented to attacker events, rows soft-deleted)\n\n- Affects multiple entity types: Attribute, Object, EventReport, Sighting, AttributeTag, ShadowAttribute\n\n- Requires only a low-privilege authenticated account with perm_add\n\nAffected versions: \u003c2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-24",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-24 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T09:56:35.584Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/9485ae40d"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix introduces a defensive save() override in the base model class that refuses to persist any record where the data array simultaneously contains a nested key matching the model alias and other top-level scalar fields, logging a warning and returning false. Additionally, all code paths that sanitize and save records (free-text import, module result processing, object delta merge, attribute bulk edit, sighting capture, shadow attribute proposal, event report creation) now explicitly unset the nested alias key from the data array before calling save(), ensuring the ORM cannot be redirected to an attacker-chosen row. Controller-level request reshaping was also corrected to avoid creating self-referencing data structures.\u003c/p\u003e"
}
],
"value": "The fix introduces a defensive save() override in the base model class that refuses to persist any record where the data array simultaneously contains a nested key matching the model alias and other top-level scalar fields, logging a warning and returning false. Additionally, all code paths that sanitize and save records (free-text import, module result processing, object delta merge, attribute bulk edit, sighting capture, shadow attribute proposal, event report creation) now explicitly unset the nested alias key from the data array before calling save(), ensuring the ORM cannot be redirected to an attacker-chosen row. Controller-level request reshaping was also corrected to avoid creating self-referencing data structures."
}
],
"title": "MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48); the exact last affected release and first fixed release are not explicitly stated in the patch.",
"PR:L assumes the attacker needs only a basic authenticated account with perm_add; the regression tests confirm a non-admin, non-sync role suffices, but the minimum permission set is not exhaustively enumerated in the patch.",
"VA:N assumes soft-delete is treated as an integrity impact (data state change) rather than an availability impact; if the organization considers soft-deleted records as unavailable, VA could be raised to L.",
"CAPEC-24 (Parameter Tampering) is the closest available pattern; the specific ORM-level key-binding manipulation does not have a dedicated CAPEC entry, so the mapping is approximate.",
"The Co-Authored-By line references an AI tool (Claude Opus 5); it is listed as a tool credit, not a human remediation developer, per CVE credit role semantics.",
"The commit date is 2026-09-25; the vulnerability may have existed for an unknown duration prior to reporting."
],
"capecRationale": [
{
"capecId": "CAPEC-24",
"rationale": "The attacker tampers with the structure of request parameters by injecting a nested key matching the model alias, causing the ORM to target a different row than the application intended. The outer parameters (sanitized id, pinned event_id) are effectively ignored in favor of the attacker-controlled inner parameters. This is a structural parameter tampering attack exploiting the ORM\u0027s data-binding semantics. The mapping is the closest available CAPEC; no more specific pattern for ORM-level key injection exists in the CAPEC catalog."
}
],
"commit": "9485ae40d334471882e3bd246651acaa68feef34",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"cvssRationale": "AV:N - MISP is a network-accessible web application. AC:L - The attack requires only crafting a request with a nested alias key; no race condition or complex state is needed. AT:N - No in-transit tampering required. PR:L - An authenticated user with basic write permission (perm_add) suffices; no admin or sync role needed. UI:N - No victim interaction required. VC:N - The attacker does not gain new read access; the impact is on data they can already partially see or infer. VI:H - The attacker can overwrite, re-parent, or soft-delete rows in the same instance, causing high integrity loss to the vulnerable component\u0027s data. VA:N - Soft-delete is a state change (integrity) rather than a service disruption. SC:N - No impact on separate components\u0027 confidentiality. SI:H - The cross-tenant nature means integrity of other organizations\u0027 data (a separate security scope) is compromised. SA:N - No security mechanism is weakened.",
"fixSummary": "The fix introduces a defensive save() override in the base model class that refuses to persist any record where the data array simultaneously contains a nested key matching the model alias and other top-level scalar fields, logging a warning and returning false. Additionally, all code paths that sanitize and save records (free-text import, module result processing, object delta merge, attribute bulk edit, sighting capture, shadow attribute proposal, event report creation) now explicitly unset the nested alias key from the data array before calling save(), ensuring the ORM cannot be redirected to an attacker-chosen row. Controller-level request reshaping was also corrected to avoid creating self-referencing data structures.",
"generatedAt": "2026-09-30T09:24:37.816321Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 6,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "03af388a5ac0d93cebef902e0050aa8496aae8d88d1496b80abc0b9a929cb39a",
"patchSummary": "Added a save() override in AppModel.php that detects and rejects ambiguous payloads containing both a nested model-alias key and outer scalars. Added unset($data[$this-\u003ealias]) calls in Event.php (free-text, module results, object attribute save), MispAttribute.php (saveAttributes, captureAttribute, editAttributeBulk), MispObject.php (deltaMerge, editObject), ShadowAttribute.php (__preCaptureMassage), and Sighting.php (captureSightings) to strip the nested alias key before save. Changed six controller files to use $this-\u003erequest-\u003edata = array(\u0027Model\u0027 =\u003e $this-\u003erequest-\u003edata) instead of $this-\u003erequest-\u003edata[\u0027Model\u0027] = $this-\u003erequest-\u003edata, preventing self-referencing structures. Added a new regression test suite (tests/testregressions.py) with cross-tenant attack scenarios and wired it into the CI workflow.",
"patchTruncated": false,
"patches": [
{
"commit": "9485ae40d334471882e3bd246651acaa68feef34",
"patchSha256": "03af388a5ac0d93cebef902e0050aa8496aae8d88d1496b80abc0b9a929cb39a",
"source": "https://github.com/MISP/MISP/commit/9485ae40d.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/9485ae40d.patch",
"subject": "fix: [security] A nested model alias key no longer selects"
}
],
"source": "https://github.com/MISP/MISP/commit/9485ae40d.patch",
"subject": "fix: [security] A nested model alias key no longer selects",
"tagVersionBoundary": {
"commits_after_fix": 23,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-639",
"rationale": "The attacker controls the row identifier (id) inside the nested alias block, which the ORM uses to select the target row. The application\u0027s authorization and sanitization (id stripping, event_id pinning) is applied to the outer record and is bypassed because the ORM binds to the inner record. This is a direct case of a user-controlled key selecting an unauthorized resource."
},
{
"cweId": "CWE-20",
"rationale": "The application fails to validate or strip the nested model-alias key from user-supplied data before passing it to the ORM. The ORM\u0027s set() method interprets this key as the record to save, contradicting the application\u0027s intent. The absence of validation on this structural aspect of the input is the root cause."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20280"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103237",
"datePublished": "2026-09-30T09:56:35.584Z",
"dateReserved": "2026-09-30T09:56:33.891Z",
"dateUpdated": "2026-09-30T17:08:51.346Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103239 (GCVE-0-2026-103239)
Vulnerability from cvelistv5 – Published: 2026-09-30 10:16 – Updated: 2026-09-30 16:50| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/96f735e7b | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 09:58 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/96f735e7b.patch
67f9b5741b88… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
96f735e7b5d9
|
fix: [security] Tag collection saves no longer write sibling | 67f9b5741b88… |
Fix summary
The fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path.
Patch summary
In TagCollectionsController.php, both addWithTags() and editWithTags() were modified. The full $this->request->data is no longer passed to saveAssociated(). Instead, only the TagCollection key is extracted from the request. The saveAssociated() call is replaced with a plain save() for the collection, followed by an explicit loop that creates and saves each TagCollectionTag row individually. In editWithTags(), the tag rewrite logic is restructured to delete existing tag associations and re-insert them after the collection save. REST success/failure response handling is added to both methods.
CVSS rationale
The vulnerability is exploitable over the network (AV:N) with low complexity (AC:L) by simply adding extra fields to a legitimate tag collection request. No special attack conditions are required (AT:N). The attacker needs an authenticated account with the tag editor permission (PR:L). No user interaction is needed (UI:N). The primary impact is on integrity (VI:H) because the attacker can create or modify User and Organisation records to escalate to site admin. Modifications can be made so data can be see (VC:H) but no availability impact (VA:N). No subsequent component is affected (SC:N, SI:N, SA:N).
Weakness rationale
- CWE-284 A user with only tag editor permissions was able to write to User and Organisation records through the bulk-association save, bypassing the intended access control boundaries. The authorization model did not restrict which associated models could be persisted.
- CWE-862 The saveAssociated() call did not enforce per-model authorization checks, allowing any associated model data in the payload to be written regardless of the caller's permissions for those models.
Attack pattern rationale
- CAPEC-126 The attacker tampers with the HTTP request by injecting additional model fields (User, Organisation) into the tag collection payload. The application's bulk-save logic processes these unexpected parameters without filtering, leading to unauthorized record creation or modification. This is the closest CAPEC to the observed attack: adding extra parameters to a legitimate request to trigger unintended side effects.
- CAPEC-1 The application accepted the entire request body without validating or restricting which model keys were present before passing it to the persistence layer. This is a secondary mapping; CAPEC-126 is more specific to the parameter-injection attack vector observed here.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48 with 24 commits after fix), suggesting the fix is included in v2.5.48. No explicit version range is stated in the patch itself.
- The privilege level required is assumed to be 'perm_tag_editor' based on the commit message; the exact permission model and whether other roles are affected is not fully verifiable from the patch alone.
- CAPEC-126 (Parameter Tampering) is selected as the closest match; the attack is more precisely a mass-assignment / sibling-model injection via an ORM bulk-save, for which no exact CAPEC exists. CAPEC-126 is the best available approximation.
- The CVSS assumes the attacker can reach the MISP web interface over the network and holds a valid session with tag editor permissions. No multi-step or race-condition requirements are evident.
- The Co-Authored-By line references an AI assistant (Claude Opus 4.8); it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103239",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:49:52.252773Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:50:57.400Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"TagCollectionsController"
],
"product": "MISP",
"programFiles": [
"app/Controller/TagCollectionsController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload.\u003c/p\u003e\u003cp\u003eA user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated account with the tag editor permission (perm_tag_editor)\u003c/p\u003e\u003cp\u003e- Network access to the MISP instance\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Unauthorized creation or modification of User and Organisation records\u003c/p\u003e\u003cp\u003e- Privilege escalation from tag editor to site administrator\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt; 2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload.\n\nA user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator.\n\nPreconditions:\n\n- An authenticated account with the tag editor permission (perm_tag_editor)\n\n- Network access to the MISP instance\n\nImpact:\n\n- Unauthorized creation or modification of User and Organisation records\n\n- Privilege escalation from tag editor to site administrator\n\nAffected versions: \u003c 2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Parameter Tampering"
}
]
},
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Improper Input Validation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "CWE-284 Improper Access Control",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T10:16:18.835Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/96f735e7b"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path.\u003c/p\u003e"
}
],
"value": "The fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path."
}
],
"title": "MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48 with 24 commits after fix), suggesting the fix is included in v2.5.48. No explicit version range is stated in the patch itself.",
"The privilege level required is assumed to be \u0027perm_tag_editor\u0027 based on the commit message; the exact permission model and whether other roles are affected is not fully verifiable from the patch alone.",
"CAPEC-126 (Parameter Tampering) is selected as the closest match; the attack is more precisely a mass-assignment / sibling-model injection via an ORM bulk-save, for which no exact CAPEC exists. CAPEC-126 is the best available approximation.",
"The CVSS assumes the attacker can reach the MISP web interface over the network and holds a valid session with tag editor permissions. No multi-step or race-condition requirements are evident.",
"The Co-Authored-By line references an AI assistant (Claude Opus 4.8); it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The attacker tampers with the HTTP request by injecting additional model fields (User, Organisation) into the tag collection payload. The application\u0027s bulk-save logic processes these unexpected parameters without filtering, leading to unauthorized record creation or modification. This is the closest CAPEC to the observed attack: adding extra parameters to a legitimate request to trigger unintended side effects."
},
{
"capecId": "CAPEC-1",
"rationale": "The application accepted the entire request body without validating or restricting which model keys were present before passing it to the persistence layer. This is a secondary mapping; CAPEC-126 is more specific to the parameter-injection attack vector observed here."
}
],
"commit": "96f735e7b5d9e28ea2eaf3d8a02ab800bad5c9ed",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "The vulnerability is exploitable over the network (AV:N) with low complexity (AC:L) by simply adding extra fields to a legitimate tag collection request. No special attack conditions are required (AT:N). The attacker needs an authenticated account with the tag editor permission (PR:L). No user interaction is needed (UI:N). The primary impact is on integrity (VI:H) because the attacker can create or modify User and Organisation records to escalate to site admin. Modifications can be made so data can be see (VC:H) but no availability impact (VA:N). No subsequent component is affected (SC:N, SI:N, SA:N).",
"fixSummary": "The fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path.",
"generatedAt": "2026-09-30T09:58:24.508004Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "67f9b5741b88384cd891423b2a8b9f5c8e071b5895b93eb337a16c7f780ee88c",
"patchSummary": "In TagCollectionsController.php, both addWithTags() and editWithTags() were modified. The full $this-\u003erequest-\u003edata is no longer passed to saveAssociated(). Instead, only the TagCollection key is extracted from the request. The saveAssociated() call is replaced with a plain save() for the collection, followed by an explicit loop that creates and saves each TagCollectionTag row individually. In editWithTags(), the tag rewrite logic is restructured to delete existing tag associations and re-insert them after the collection save. REST success/failure response handling is added to both methods.",
"patchTruncated": false,
"patches": [
{
"commit": "96f735e7b5d9e28ea2eaf3d8a02ab800bad5c9ed",
"patchSha256": "67f9b5741b88384cd891423b2a8b9f5c8e071b5895b93eb337a16c7f780ee88c",
"source": "https://github.com/MISP/MISP/commit/96f735e7b.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/96f735e7b.patch",
"subject": "fix: [security] Tag collection saves no longer write sibling"
}
],
"source": "https://github.com/MISP/MISP/commit/96f735e7b.patch",
"subject": "fix: [security] Tag collection saves no longer write sibling",
"tagVersionBoundary": {
"commits_after_fix": 24,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-284",
"rationale": "A user with only tag editor permissions was able to write to User and Organisation records through the bulk-association save, bypassing the intended access control boundaries. The authorization model did not restrict which associated models could be persisted."
},
{
"cweId": "CWE-862",
"rationale": "The saveAssociated() call did not enforce per-model authorization checks, allowing any associated model data in the payload to be written regardless of the caller\u0027s permissions for those models."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20019"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103239",
"datePublished": "2026-09-30T10:16:18.835Z",
"dateReserved": "2026-09-30T10:16:15.941Z",
"dateUpdated": "2026-09-30T16:50:57.400Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103321 (GCVE-0-2026-103321)
Vulnerability from cvelistv5 – Published: 2026-09-30 12:19 – Updated: 2026-09-30 12:44| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/92c7ccc43 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 11:21 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/92c7ccc43.patch
0ecb893de300… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
92c7ccc4398a
|
fix: [security] Validate the event graph preview and stop | 0ecb893de300… |
Fix summary
The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.
Patch summary
In app/Model/EventGraph.php, a new validation rule is added for the preview_img field requiring it to match the regex /^data:image\/png;base64,[A-Za-z0-9+\/]*={0,2}$/ (allowing empty). In app/webroot/js/event-graph.js, two occurrences of string-concatenated img tag construction (return '<img ... src="' + value + '" />') are replaced with jQuery DOM construction using $('<img ...>').prop('src', value), which sets the attribute safely without HTML parsing.
CVSS rationale
AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special conditions required; storing a crafted value and viewing the graph is straightforward. AT:N: no manipulation of the attack target needed. PR:L: attacker needs a low-privilege authenticated MISP account to create/modify an event graph. UI:P: the victim passively triggers the XSS by viewing the event graph preview (hovering a button), a normal workflow action. VC/VI/VA:N: the MISP server itself is not compromised; the impact is in the victim's browser. SC:H: the attacker can read cookies, tokens, and data in the victim's session. SI:H: the attacker can perform authenticated actions as the victim. SA:N: no availability impact on the victim's system.
Weakness rationale
- CWE-79 The stored preview_img value was rendered into an HTML attribute via string concatenation without sufficient neutralization, enabling script injection in the victim's browser. This is a textbook stored XSS.
- CWE-20 The server accepted and persisted the preview_img field without any format validation, allowing arbitrary content to be stored and later rendered. The fix adds a strict regex validation rule.
Attack pattern rationale
- CAPEC-1 The patch directly addresses a stored XSS where attacker-controlled data is rendered into a web page without proper encoding or validation. CAPEC-1 is the canonical attack pattern for XSS and is the closest match. No uncertainty in this mapping; the commit message explicitly identifies the issue as stored XSS.
Assumptions to verify
- The affected version range is inferred from the tag_version_boundary (v2.5.48 with 43 commits after the fix); the exact fixed release version is not stated in the patch metadata.
- PR:L assumes the attacker needs at least a basic authenticated MISP account to create or modify an event graph entry; the patch does not specify the exact permission level required.
- UI:P assumes the victim triggers the XSS by viewing the event graph preview as part of normal workflow (hovering the plot button), which is a passive interaction rather than an active click on a crafted link.
- The CAPEC-1 mapping is direct and unambiguous given the explicit stored XSS identification in the commit message.
- The Co-Authored-By line referencing Claude Opus 4.8 is treated as a tool credit per the commit metadata; it is not a human contributor.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103321",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T12:44:13.205587Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T12:44:22.064Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"EventGraph model",
"event-graph.js client-side rendering"
],
"product": "MISP",
"programFiles": [
"app/Model/EventGraph.php",
"app/webroot/js/event-graph.js"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\u003c/p\u003e\u003cp\u003eThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element\u0027s src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated MISP user with the ability to create or modify an event graph entry.\u003c/p\u003e\u003cp\u003e- A second user (the victim) who views the event graph and triggers the preview popover.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\u003c/p\u003e\u003cp\u003e- Potential theft of session tokens, cookies, or sensitive data accessible to the victim\u0027s browser.\u003c/p\u003e\u003cp\u003e- Potential for performing actions on behalf of the victim within the MISP application.\u003c/p\u003e\u003cp\u003eAffected: MISP versions prior to the fix (commit applied after v2.5.48).\u003c/p\u003e"
}
],
"value": "MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\n\nThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element\u0027s src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\n\nPreconditions:\n\n- An authenticated MISP user with the ability to create or modify an event graph entry.\n\n- A second user (the victim) who views the event graph and triggers the preview popover.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\n\n- Potential theft of session tokens, cookies, or sensitive data accessible to the victim\u0027s browser.\n\n- Potential for performing actions on behalf of the victim within the MISP application.\n\nAffected: MISP versions prior to the fix (commit applied after v2.5.48)."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting (XSS)"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T12:19:01.829Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/92c7ccc43"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML."
}
],
"title": "MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag_version_boundary (v2.5.48 with 43 commits after the fix); the exact fixed release version is not stated in the patch metadata.",
"PR:L assumes the attacker needs at least a basic authenticated MISP account to create or modify an event graph entry; the patch does not specify the exact permission level required.",
"UI:P assumes the victim triggers the XSS by viewing the event graph preview as part of normal workflow (hovering the plot button), which is a passive interaction rather than an active click on a crafted link.",
"The CAPEC-1 mapping is direct and unambiguous given the explicit stored XSS identification in the commit message.",
"The Co-Authored-By line referencing Claude Opus 4.8 is treated as a tool credit per the commit metadata; it is not a human contributor."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The patch directly addresses a stored XSS where attacker-controlled data is rendered into a web page without proper encoding or validation. CAPEC-1 is the canonical attack pattern for XSS and is the closest match. No uncertainty in this mapping; the commit message explicitly identifies the issue as stored XSS."
}
],
"commit": "92c7ccc4398a64e61699bd79fb4010703616fc59",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special conditions required; storing a crafted value and viewing the graph is straightforward. AT:N: no manipulation of the attack target needed. PR:L: attacker needs a low-privilege authenticated MISP account to create/modify an event graph. UI:P: the victim passively triggers the XSS by viewing the event graph preview (hovering a button), a normal workflow action. VC/VI/VA:N: the MISP server itself is not compromised; the impact is in the victim\u0027s browser. SC:H: the attacker can read cookies, tokens, and data in the victim\u0027s session. SI:H: the attacker can perform authenticated actions as the victim. SA:N: no availability impact on the victim\u0027s system.",
"fixSummary": "The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.",
"generatedAt": "2026-09-30T11:21:27.655462Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "0ecb893de30056bc3f9609fcb8de43d60b1cedd6a1eea7d6aa53ef6d351d642a",
"patchSummary": "In app/Model/EventGraph.php, a new validation rule is added for the preview_img field requiring it to match the regex /^data:image\\/png;base64,[A-Za-z0-9+\\/]*={0,2}$/ (allowing empty). In app/webroot/js/event-graph.js, two occurrences of string-concatenated img tag construction (return \u0027\u003cimg ... src=\"\u0027 + value + \u0027\" /\u003e\u0027) are replaced with jQuery DOM construction using $(\u0027\u003cimg ...\u003e\u0027).prop(\u0027src\u0027, value), which sets the attribute safely without HTML parsing.",
"patchTruncated": false,
"patches": [
{
"commit": "92c7ccc4398a64e61699bd79fb4010703616fc59",
"patchSha256": "0ecb893de30056bc3f9609fcb8de43d60b1cedd6a1eea7d6aa53ef6d351d642a",
"source": "https://github.com/MISP/MISP/commit/92c7ccc43.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/92c7ccc43.patch",
"subject": "fix: [security] Validate the event graph preview and stop"
}
],
"source": "https://github.com/MISP/MISP/commit/92c7ccc43.patch",
"subject": "fix: [security] Validate the event graph preview and stop",
"tagVersionBoundary": {
"commits_after_fix": 43,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The stored preview_img value was rendered into an HTML attribute via string concatenation without sufficient neutralization, enabling script injection in the victim\u0027s browser. This is a textbook stored XSS."
},
{
"cweId": "CWE-20",
"rationale": "The server accepted and persisted the preview_img field without any format validation, allowing arbitrary content to be stored and later rendered. The fix adds a strict regex validation rule."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20294"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103321",
"datePublished": "2026-09-30T12:19:01.829Z",
"dateReserved": "2026-09-30T12:18:54.232Z",
"dateUpdated": "2026-09-30T12:44:22.064Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103388 (GCVE-0-2026-103388)
Vulnerability from cvelistv5 – Published: 2026-09-30 14:22 – Updated: 2026-09-30 15:28- CWE-79 - Improper Neutralization of Input in Web Page ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/118528767 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 14:12 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/118528767.patch
b68dbd672692… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
118528767735
|
fix: [security] Link a galaxy cluster source only when it is | b68dbd672692… |
Fix summary
The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme.
Patch summary
Two view templates are modified. In app/View/GalaxyClusters/view.ctp, the source value is extracted into a local variable and the conditional for rendering an anchor tag now requires both FILTER_VALIDATE_URL and a preg_match against /^https?:\/\//i. In app/View/Themed/Overmind/Elements/GalaxyClusters/View/galaxy_clusters_general.ctp, the same preg_match guard is added to the existing FILTER_VALIDATE_URL check. Net effect: only http(s) URLs produce a clickable link; all other values (including javascript:) are rendered as plain escaped text.
CVSS rationale
AV:N – MISP is a web application accessed over the network. AC:L – no race conditions or special environment needed; storing a javascript: URL is straightforward. AT:N – no manipulation of the attack target required. PR:L – attacker needs galaxy editor privileges (authenticated, non-admin role). UI:A – victim must click the malicious link for script execution. VC/VI/VA:N – the MISP server itself is not directly compromised; impact is on the victim's browser. SC:H – attacker can read cookies, session tokens, and manipulate the DOM in the victim's session. SI:H – attacker can perform actions on behalf of the victim within MISP. SA:N – no direct compromise of the application's security controls or system integrity.
Weakness rationale
- CWE-79 The application renders user-controlled data (the galaxy cluster source field) into an HTML anchor tag without restricting the URI scheme to safe values. Although output is HTML-escaped via h(), the href attribute still accepts javascript: URIs, resulting in stored XSS. CWE-79 is the narrowest defensible mapping.
Attack pattern rationale
- CAPEC-64 The attack pattern involves storing a malicious payload (a javascript: URL) in a persistent data field (galaxy cluster source) that is later rendered in a web page, executing script in the victim's browser upon interaction. This is a textbook persistent/stored XSS. CAPEC-64 is the closest and most precise match in the CAPEC catalog.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 26 commits after fix); the exact first affected release is not stated in the patch.
- PR:L assumes galaxy editor privileges are a non-admin, role-based permission; the exact privilege model is not detailed in the patch.
- UI:A assumes the victim must actively click the rendered link; passive rendering without click does not execute the script.
- The CAPEC-64 mapping is the closest available pattern for stored XSS; no CAPEC specifically covers URI-scheme-based stored XSS, so CAPEC-64 is the best fit.
- The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103388",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:58:39.451751Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:06.980Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"GalaxyClusters view (default theme)",
"GalaxyClusters view (Overmind theme)"
],
"product": "MISP",
"programFiles": [
"app/View/GalaxyClusters/view.ctp",
"app/View/Themed/Overmind/Elements/GalaxyClusters/View/galaxy_clusters_general.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP\u0027s FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source.\u003c/p\u003e\u003cp\u003eWhen another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim\u0027s browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- Attacker must hold galaxy editor privileges (local or via sync).\u003c/p\u003e\u003cp\u003e- Victim must view the affected cluster and click the malicious link.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Stored cross-site scripting (XSS) in the victim\u0027s browser.\u003c/p\u003e\u003cp\u003e- Potential session theft, credential harvesting, or unauthorized actions within the MISP application.\u003c/p\u003e\u003cp\u003eAffected: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP\u0027s FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source.\n\nWhen another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim\u0027s browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim.\n\nPreconditions:\n\n- Attacker must hold galaxy editor privileges (local or via sync).\n\n- Victim must view the affected cluster and click the malicious link.\n\nImpact:\n\n- Stored cross-site scripting (XSS) in the victim\u0027s browser.\n\n- Potential session theft, credential harvesting, or unauthorized actions within the MISP application.\n\nAffected: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-64",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-64 XSS - Persistent"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input in Web Page (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:22:36.271Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/118528767"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme.\u003c/p\u003e"
}
],
"value": "The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme."
}
],
"title": "MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 26 commits after fix); the exact first affected release is not stated in the patch.",
"PR:L assumes galaxy editor privileges are a non-admin, role-based permission; the exact privilege model is not detailed in the patch.",
"UI:A assumes the victim must actively click the rendered link; passive rendering without click does not execute the script.",
"The CAPEC-64 mapping is the closest available pattern for stored XSS; no CAPEC specifically covers URI-scheme-based stored XSS, so CAPEC-64 is the best fit.",
"The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-64",
"rationale": "The attack pattern involves storing a malicious payload (a javascript: URL) in a persistent data field (galaxy cluster source) that is later rendered in a web page, executing script in the victim\u0027s browser upon interaction. This is a textbook persistent/stored XSS. CAPEC-64 is the closest and most precise match in the CAPEC catalog."
}
],
"commit": "11852876773554d79ff57937a235d18a1e4473dc",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N \u2013 MISP is a web application accessed over the network. AC:L \u2013 no race conditions or special environment needed; storing a javascript: URL is straightforward. AT:N \u2013 no manipulation of the attack target required. PR:L \u2013 attacker needs galaxy editor privileges (authenticated, non-admin role). UI:A \u2013 victim must click the malicious link for script execution. VC/VI/VA:N \u2013 the MISP server itself is not directly compromised; impact is on the victim\u0027s browser. SC:H \u2013 attacker can read cookies, session tokens, and manipulate the DOM in the victim\u0027s session. SI:H \u2013 attacker can perform actions on behalf of the victim within MISP. SA:N \u2013 no direct compromise of the application\u0027s security controls or system integrity.",
"fixSummary": "The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme.",
"generatedAt": "2026-09-30T14:12:32.112077Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "b68dbd6726929ff1680daeae2a273fc346e7075d7ded36195994315c19ccf278",
"patchSummary": "Two view templates are modified. In app/View/GalaxyClusters/view.ctp, the source value is extracted into a local variable and the conditional for rendering an anchor tag now requires both FILTER_VALIDATE_URL and a preg_match against /^https?:\\/\\//i. In app/View/Themed/Overmind/Elements/GalaxyClusters/View/galaxy_clusters_general.ctp, the same preg_match guard is added to the existing FILTER_VALIDATE_URL check. Net effect: only http(s) URLs produce a clickable link; all other values (including javascript:) are rendered as plain escaped text.",
"patchTruncated": false,
"patches": [
{
"commit": "11852876773554d79ff57937a235d18a1e4473dc",
"patchSha256": "b68dbd6726929ff1680daeae2a273fc346e7075d7ded36195994315c19ccf278",
"source": "https://github.com/MISP/MISP/commit/118528767.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/118528767.patch",
"subject": "fix: [security] Link a galaxy cluster source only when it is"
}
],
"source": "https://github.com/MISP/MISP/commit/118528767.patch",
"subject": "fix: [security] Link a galaxy cluster source only when it is",
"tagVersionBoundary": {
"commits_after_fix": 26,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The application renders user-controlled data (the galaxy cluster source field) into an HTML anchor tag without restricting the URI scheme to safe values. Although output is HTML-escaped via h(), the href attribute still accepts javascript: URIs, resulting in stored XSS. CWE-79 is the narrowest defensible mapping."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20256"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103388",
"datePublished": "2026-09-30T14:22:36.271Z",
"dateReserved": "2026-09-30T14:22:32.098Z",
"dateUpdated": "2026-09-30T15:28:06.980Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103389 (GCVE-0-2026-103389)
Vulnerability from cvelistv5 – Published: 2026-09-30 14:25 – Updated: 2026-09-30 15:28| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/8ea5783dd | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 14:24 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/8ea5783dd.patch
382869c811e8… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
8ea5783ddcfe
|
fix: [security] Galaxy icons are icon names, and the | 382869c811e8… |
Fix summary
The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.
Patch summary
Added a static isValidIconName() method and a regex constant (ICON_NAME_PATTERN) to the Galaxy model, plus a model-level validation rule restricting the icon field to lowercase letters, digits, and dashes. The captureGalaxy() method now blanks out any icon value that fails validation before persistence. CorrelationGraphTool::__createNode() now checks the icon against the validator and substitutes 'globe' for invalid stored values. Both correlation-graph.js and correlation-graphOvermind.js were changed from .html() string concatenation to .attr('class', ...) with a regex strip of non-conforming characters. AppController asset query version bumped from 225 to 226. A new PHPUnit test file (GalaxyIconNameTest.php) validates the icon name rule against known-good and known-bad payloads including the originally reported XSS vector.
CVSS rationale
AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special timing; simply set the icon field and wait for a victim to view the graph. AT:N: no manipulation of the attack target required. PR:L: requires an authenticated user with perm_galaxy_editor, which is the default stock User role. UI:A: the victim must actively open the correlation graph of an event containing the affected galaxy cluster. VC/VI/VA:N: the server-side application is not directly compromised; the impact is on the victim's browser session. SC:H: script execution in the victim's session can read cookies, tokens, and sensitive page data. SI:H: the attacker can modify the victim's view, inject content, or trigger actions. SA:N: no availability impact on the system.
Weakness rationale
- CWE-79 The galaxy icon field was stored without validation and later rendered into the DOM via D3 .html(), allowing an attacker to inject and execute arbitrary script in the victim's browser. This is a textbook stored XSS.
- CWE-20 The root enabler is the absence of any server-side validation on the icon field at write time (add, edit, capture). The field accepted arbitrary strings including HTML markup, which was the precondition for the XSS.
Attack pattern rationale
- CAPEC-1 The attack pattern is a stored XSS: an authenticated user with galaxy editor permission injects a script payload into a persistent data field (galaxy icon), which is later rendered unsanitized in another user's browser via the correlation graph. CAPEC-1 is the closest and most direct match. No more specific CAPEC entry for stored XSS via a data field rendered by a graphing library exists in the CAPEC catalog, so CAPEC-1 is the best available mapping.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata indicating the fix commit precedes v2.5.48 by 20 commits; no explicit 'fixed in' version is stated in the patch itself.
- The perm_galaxy_editor permission is assumed to be granted to the stock User role as stated in the commit message; the exact role-permission mapping was not independently verified from the patch.
- CAPEC-1 is the closest available mapping; no CAPEC entry specifically describes stored XSS via a graph-rendering library data field, so the general Cross Site Scripting pattern is used.
- CVSS UI:A assumes the victim must navigate to the correlation graph view of a specific event; if the graph is auto-loaded on a commonly visited page, UI could be lowered to Passive.
- The Co-Authored-By line references an AI assistant (Claude Fable 5.1); it is recorded as a tool credit rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103389",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:58:27.715153Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:06.728Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Galaxy model",
"Correlation Graph (default theme)",
"Correlation Graph (Overmind theme)",
"Galaxy sync/import capture"
],
"product": "MISP",
"programFiles": [
"app/Model/Galaxy.php",
"app/Lib/Tools/CorrelationGraphTool.php",
"app/webroot/js/correlation-graph.js",
"app/webroot/js/correlation-graphOvermind.js"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Fable 5.1"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.\u003c/p\u003e\u003cp\u003eA user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Arbitrary script execution in the context of the victim\u0027s MISP session\u003c/p\u003e\u003cp\u003e- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim\u003c/p\u003e\u003cp\u003e- Affects both the default and Overmind UI themes\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.\n\nA user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.\n\nImpact:\n\n- Arbitrary script execution in the context of the victim\u0027s MISP session\n\n- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim\n\n- Affects both the default and Overmind UI themes\n\nAffected versions: \u003c2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:25:59.230Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/8ea5783dd"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts."
}
],
"title": "MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata indicating the fix commit precedes v2.5.48 by 20 commits; no explicit \u0027fixed in\u0027 version is stated in the patch itself.",
"The perm_galaxy_editor permission is assumed to be granted to the stock User role as stated in the commit message; the exact role-permission mapping was not independently verified from the patch.",
"CAPEC-1 is the closest available mapping; no CAPEC entry specifically describes stored XSS via a graph-rendering library data field, so the general Cross Site Scripting pattern is used.",
"CVSS UI:A assumes the victim must navigate to the correlation graph view of a specific event; if the graph is auto-loaded on a commonly visited page, UI could be lowered to Passive.",
"The Co-Authored-By line references an AI assistant (Claude Fable 5.1); it is recorded as a tool credit rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The attack pattern is a stored XSS: an authenticated user with galaxy editor permission injects a script payload into a persistent data field (galaxy icon), which is later rendered unsanitized in another user\u0027s browser via the correlation graph. CAPEC-1 is the closest and most direct match. No more specific CAPEC entry for stored XSS via a data field rendered by a graphing library exists in the CAPEC catalog, so CAPEC-1 is the best available mapping."
}
],
"commit": "8ea5783ddcfe69be6013337a0d6732ac75a862e6",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Fable 5.1"
},
{
"lang": "en",
"type": "tool",
"value": "Claude Fable 5.1"
}
],
"cvssRationale": "AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special timing; simply set the icon field and wait for a victim to view the graph. AT:N: no manipulation of the attack target required. PR:L: requires an authenticated user with perm_galaxy_editor, which is the default stock User role. UI:A: the victim must actively open the correlation graph of an event containing the affected galaxy cluster. VC/VI/VA:N: the server-side application is not directly compromised; the impact is on the victim\u0027s browser session. SC:H: script execution in the victim\u0027s session can read cookies, tokens, and sensitive page data. SI:H: the attacker can modify the victim\u0027s view, inject content, or trigger actions. SA:N: no availability impact on the system.",
"fixSummary": "The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.",
"generatedAt": "2026-09-30T14:24:01.890608Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "382869c811e8df5875a463c4b6275f754f4969445196f08d708cfee926528b0f",
"patchSummary": "Added a static isValidIconName() method and a regex constant (ICON_NAME_PATTERN) to the Galaxy model, plus a model-level validation rule restricting the icon field to lowercase letters, digits, and dashes. The captureGalaxy() method now blanks out any icon value that fails validation before persistence. CorrelationGraphTool::__createNode() now checks the icon against the validator and substitutes \u0027globe\u0027 for invalid stored values. Both correlation-graph.js and correlation-graphOvermind.js were changed from .html() string concatenation to .attr(\u0027class\u0027, ...) with a regex strip of non-conforming characters. AppController asset query version bumped from 225 to 226. A new PHPUnit test file (GalaxyIconNameTest.php) validates the icon name rule against known-good and known-bad payloads including the originally reported XSS vector.",
"patchTruncated": false,
"patches": [
{
"commit": "8ea5783ddcfe69be6013337a0d6732ac75a862e6",
"patchSha256": "382869c811e8df5875a463c4b6275f754f4969445196f08d708cfee926528b0f",
"source": "https://github.com/MISP/MISP/commit/8ea5783dd.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/8ea5783dd.patch",
"subject": "fix: [security] Galaxy icons are icon names, and the"
}
],
"source": "https://github.com/MISP/MISP/commit/8ea5783dd.patch",
"subject": "fix: [security] Galaxy icons are icon names, and the",
"tagVersionBoundary": {
"commits_after_fix": 20,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The galaxy icon field was stored without validation and later rendered into the DOM via D3 .html(), allowing an attacker to inject and execute arbitrary script in the victim\u0027s browser. This is a textbook stored XSS."
},
{
"cweId": "CWE-20",
"rationale": "The root enabler is the absence of any server-side validation on the icon field at write time (add, edit, capture). The field accepted arbitrary strings including HTML markup, which was the precondition for the XSS."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20142"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103389",
"datePublished": "2026-09-30T14:25:59.230Z",
"dateReserved": "2026-09-30T14:25:56.802Z",
"dateUpdated": "2026-09-30T15:28:06.728Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.