CVE-2026-94373 Overview
CVE-2026-94373 is a DOM-based cross-site scripting (XSS) vulnerability in Malware Information Sharing Platform (MISP) versions prior to 2.5.47. The flaw exists in the ContextualMenu JavaScript class, which assigns user-controllable strings to the innerHTML property of <option> elements. Because innerHTML parses HTML markup, untrusted input is rendered as live DOM content rather than plain text. An authenticated user who can influence data displayed in the contextual menu can inject arbitrary HTML or JavaScript executing within the MISP origin. The issue is tracked under [CWE-79].
Critical Impact
Successful exploitation enables session hijacking, data exfiltration from threat intelligence stores, and unauthorized actions performed as the victim user within the MISP application.
Affected Products
- MISP versions prior to 2.5.47
- MISP web interface component app/webroot/js/contextual_menu.js
- Deployments exposing the contextual menu to multi-user threat intelligence workflows
Discovery Timeline
- 2026-09-21 - CVE-2026-94373 published to NVD
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-94373
Vulnerability Analysis
The vulnerability resides in the ContextualMenu class within app/webroot/js/contextual_menu.js. The component builds <option> elements dynamically and populates their text through the innerHTML property. Assigning a string to innerHTML invokes the browser's HTML parser, converting markup such as <img src=x onerror=...> into executable DOM nodes. Because MISP renders threat intelligence data supplied by multiple users and feeds, an attacker who controls attribute values, tag names, or event titles displayed in the menu can smuggle script payloads into the client. Execution occurs within the authenticated MISP origin, granting the payload access to session cookies, API tokens accessible from the DOM, and any action available to the victim's role.
Root Cause
The root cause is unsafe sink selection in DOM manipulation. The code uses innerHTML where textContent was required. innerHTML treats input as HTML, while textContent treats input as literal text, neutralizing markup. The absence of contextual output encoding on both the object and scalar branches of the option builder produces the injection point.
Attack Vector
Exploitation requires an attacker with low privileges to insert crafted content into a MISP object, attribute, tag, or related field that is later rendered by the contextual menu. When a victim opens that menu, the browser parses the malicious markup and executes the injected script. User interaction is required to open the menu, which aligns with the passive user-interaction requirement in the scoring vector.
// Patch from app/webroot/js/contextual_menu.js
var option = document.createElement('option');
if (typeof value === 'object') {
option.value = value.value;
- option.innerHTML = value.text;
+ option.textContent = value.text;
} else {
option.value = value;
- option.innerHTML = value;
+ option.textContent = value;
}
select.appendChild(option);
Source: GitHub MISP Commit b062698f2. The fix replaces innerHTML with textContent, causing the browser to render the string as inert text and eliminating the script execution path.
Detection Methods for CVE-2026-94373
Indicators of Compromise
- MISP objects, attributes, or tags containing HTML tags such as <script>, <img onerror=>, or <svg onload=> in fields consumed by the contextual menu.
- Outbound browser requests from analyst workstations to unfamiliar domains immediately after opening MISP contextual menus.
- Unexpected API calls executed under an analyst account without corresponding user actions in server logs.
Detection Strategies
- Review the MISP database for stored attribute and tag values matching HTML or JavaScript patterns using regular expression searches against attributes.value1, attributes.value2, and tags.name.
- Inspect browser Content Security Policy (CSP) violation reports for inline script or event handler violations originating from the MISP origin.
- Correlate MISP audit log entries for object creation with subsequent authenticated actions from the same session to identify anomalous flows.
Monitoring Recommendations
- Enable and centralize MISP audit logs, forwarding them to a SIEM for pattern analysis of injection attempts against string fields.
- Monitor web server access logs for POST requests to MISP object and attribute endpoints containing encoded HTML payloads.
- Track browser telemetry from analyst workstations for anomalous DOM mutations or script execution when interacting with MISP.
How to Mitigate CVE-2026-94373
Immediate Actions Required
- Upgrade MISP to version 2.5.47 or later, which contains commit b062698f2 replacing innerHTML with textContent in contextual_menu.js.
- Audit existing MISP content for stored HTML or JavaScript payloads in attribute values, object names, and tag fields.
- Rotate MISP session tokens and API keys for accounts that may have opened contextual menus rendering untrusted content.
Patch Information
The upstream fix is committed to the MISP repository at GitHub MISP Commit b062698f2. The patch modifies app/webroot/js/contextual_menu.js so that option text is assigned via textContent, which does not parse HTML markup. Deploy the fix by upgrading to MISP 2.5.47 or later through the standard update procedure documented by the MISP project.
Workarounds
- Restrict MISP write access to trusted analysts pending patch deployment to limit who can inject content rendered by the contextual menu.
- Deploy a strict Content Security Policy that disallows inline scripts and event handlers on the MISP origin to blunt DOM XSS execution.
- Apply the two-line source change from commit b062698f2 manually to app/webroot/js/contextual_menu.js if upgrading is not immediately feasible.
# Apply the upstream patch manually on an unpatched MISP deployment
cd /var/www/MISP
git fetch origin
git cherry-pick b062698f2
# Verify the fix
grep -n "textContent" app/webroot/js/contextual_menu.js
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
