{"id":"CVE-2026-104906","summary":"MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output","details":"MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim's MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim's MISP session.\n\nPreconditions:\n\n- The victim must be an authenticated MISP user with access to the TAXII object viewer.\n\n- The victim must open or view the crafted TAXII object.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim's browser within the MISP application context.\n\n- Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface.\n\n- Potential for performing actions on behalf of the authenticated user.\n\nAffected versions: \u003c2.5.48.","modified":"2026-10-04T02:46:02.024312773Z","published":"2026-10-02T15:49:32.948Z","database_specific":{"cna_assigner":"CIRCL","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104906.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104906.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104906"},{"type":"FIX","url":"https://github.com/MISP/MISP/commit/1bed4ca0c"},{"type":"PACKAGE","url":"https://github.com/MISP/MISP"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/misp/misp","events":[{"introduced":"0"},{"fixed":"1bed4ca0c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.5.48"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104906.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"}]}