{"id":"CVE-2026-103662","summary":"MISP Reflected XSS in Taxonomy Tag Confirmation Forms","details":"MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).\n\nThe affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator's browser session.\n\nPreconditions:\n\n- The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.\n\n- The victim must be an authenticated site administrator.\n\n- The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).\n\nSecurity impact:\n\n- Execution of arbitrary client-side script in the context of the administrator's browser.\n\n- Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.\n\n- Potential for performing privileged actions on behalf of the administrator within the MISP interface.\n\nAffected versions: \u003c2.5.48.","modified":"2026-10-04T02:46:29.118066823Z","published":"2026-10-01T08:48:38.222Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103662.json","cna_assigner":"CIRCL"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103662.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103662"},{"type":"FIX","url":"https://github.com/MISP/MISP/commit/9619083c8"},{"type":"PACKAGE","url":"https://github.com/MISP/MISP"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/misp/misp","events":[{"introduced":"0"},{"fixed":"9619083c8"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.5.48"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103662.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}