CVE-2026-95661
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
22/09/2026
Last modified:
22/09/2026
Description
MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can cause an authenticated MISP user to visit a crafted URL containing a malicious type value can execute arbitrary JavaScript in the victim&#39;s browser within the MISP application origin.<br />
<br />
Successful exploitation allows the attacker to read session cookies, perform actions on behalf of the victim, or exfiltrate sensitive data accessible from the MISP interface. <br />
<br />
The vulnerability requires the victim to be authenticated and to actively navigate to the attacker-supplied URL.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM


