CVE-2026-95661

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
22/09/2026
Last modified:
22/09/2026

Description

MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can cause an authenticated MISP user to visit a crafted URL containing a malicious type value can execute arbitrary JavaScript in the victim&amp;#39;s browser within the MISP application origin.<br /> <br /> Successful exploitation allows the attacker to read session cookies, perform actions on behalf of the victim, or exfiltrate sensitive data accessible from the MISP interface. <br /> <br /> The vulnerability requires the victim to be authenticated and to actively navigate to the attacker-supplied URL.

References to Advisories, Solutions, and Tools