Skip to main content
Vulnerability Database/CVE-2026-95661

CVE-2026-95661: MISP Attribute Histogram XSS Vulnerability

CVE-2026-95661 is a reflected XSS flaw in MISP that allows attackers to execute malicious JavaScript through crafted URLs in the attribute histogram view. This post covers technical details, exploitation risks, and mitigation strategies.

Published:

CVE-2026-95661 Overview

CVE-2026-95661 is a reflected cross-site scripting (XSS) vulnerability in the Malware Information Sharing Platform (MISP) attribute histogram view. The $selectedTypes variable, derived from a URL path segment, is interpolated directly into a JavaScript array literal inside an onClick HTML attribute without encoding or escaping. An attacker who convinces an authenticated MISP user to visit a crafted URL can execute arbitrary JavaScript in the victim's browser within the MISP application origin. The flaw is classified under CWE-79.

Critical Impact

Successful exploitation allows attackers to read session cookies, perform actions on behalf of the authenticated victim, or exfiltrate sensitive threat intelligence data accessible through the MISP interface.

Affected Products

  • MISP (Malware Information Sharing Platform)
  • MISP versions prior to commit 95b8f21f6
  • The app/View/Elements/histogram.ctp view component

Discovery Timeline

  • 2026-09-22 - CVE CVE-2026-95661 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-95661

Vulnerability Analysis

The vulnerability resides in the attribute histogram view rendered by app/View/Elements/histogram.ctp. MISP builds an onClick handler that calls toggleHistogramType() and passes a JavaScript array constructed by iterating over $selectedTypes values taken from the request URL. The pre-patch template concatenated each type value into a JavaScript string literal without escaping. An attacker who supplies a malicious type value in the URL path can break out of the string literal and inject arbitrary JavaScript. Because the payload executes under the MISP origin, it inherits the session context of any authenticated user who follows the link.

Root Cause

The root cause is unsafe interpolation of user-controlled input into a JavaScript context. The template used raw PHP string concatenation inside an onClick attribute instead of a context-aware encoder. Applying HTML escaping alone would not have addressed the JavaScript execution context. The fix replaces the manual loop with json_encode() using the JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_QUOT | JSON_HEX_AMP flags to safely serialize the array.

Attack Vector

Exploitation requires the victim to be authenticated to MISP and to actively navigate to an attacker-supplied URL. The attacker crafts a URL containing a malicious selectedTypes path segment. When the histogram element renders, the injected JavaScript executes in the victim's browser and can access session cookies, issue authenticated API requests, or exfiltrate data displayed in the MISP UI.

text
// Patch diff for app/View/Elements/histogram.ctp
?>
    <div class="attributehistogram-legend-line">
        <div class="attributehistogram-legend-box" style="..."> </div>
-       <div ... onClick='toggleHistogramType("<?php echo h($type); ?>", [<?php foreach ($selectedTypes as $t) echo '"' . $t . '", ' ?>]);'><?php echo h($type);?></div>
+       <div ... onClick='toggleHistogramType("<?php echo h($type); ?>", <?php echo json_encode($selectedTypes, JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_QUOT | JSON_HEX_AMP); ?>);'><?php echo h($type);?></div>
    </div>
<?php
    $cnt++;

Source: MISP commit 95b8f21f6. The patch replaces the unsafe foreach loop with json_encode() and hexadecimal escaping flags that neutralize characters used to break out of the JavaScript literal.

Detection Methods for CVE-2026-95661

Indicators of Compromise

  • Requests to MISP histogram endpoints containing suspicious characters in the selectedTypes path segment, such as quotes, angle brackets, backslashes, or script fragments.
  • Web server access logs showing URL paths with unusually long or encoded selectedTypes values delivered via phishing links or referrers external to the MISP deployment.
  • Outbound HTTP requests from user browsers to attacker-controlled hosts immediately after loading a histogram page.

Detection Strategies

  • Deploy a web application firewall (WAF) rule that inspects the selectedTypes URL segment for XSS payload patterns before requests reach MISP.
  • Enable and alert on Content Security Policy (CSP) violation reports for the MISP origin to catch inline script execution attempts.
  • Correlate MISP application logs with proxy telemetry to identify authenticated users who accessed histogram URLs with anomalous path parameters.

Monitoring Recommendations

  • Monitor MISP audit logs for unexpected API actions performed shortly after users click external links, which may indicate session-riding via injected JavaScript.
  • Track user reports of unexpected redirects, popups, or credential prompts inside the MISP interface.
  • Review authentication and session logs for concurrent sessions or token reuse from unfamiliar IP addresses following histogram access.

How to Mitigate CVE-2026-95661

Immediate Actions Required

  • Update MISP to a version that includes commit 95b8f21f6 or later, which properly escapes the $selectedTypes variable in the histogram view.
  • Instruct MISP users to avoid clicking histogram URLs received from untrusted sources until the patch is applied.
  • Rotate session cookies and API keys for any users suspected of visiting a malicious histogram URL.

Patch Information

The upstream fix is available in MISP commit 95b8f21f6. The patch modifies app/View/Elements/histogram.ctp to serialize $selectedTypes with json_encode() and the JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_QUOT | JSON_HEX_AMP flags, preventing injected characters from breaking out of the JavaScript array literal.

Workarounds

  • Restrict access to the MISP web interface behind a reverse proxy that filters or rejects requests containing suspicious characters in the histogram URL path.
  • Enforce a strict Content Security Policy that disallows inline event handlers and unsafe-inline scripts on the MISP origin.
  • Temporarily disable or hide the attribute histogram view for user roles that do not require it until the patch is deployed.
bash
# Example nginx rule to block quote and angle bracket characters in the histogram path
location ~* ^/attributes/attributeHistogram/ {
    if ($request_uri ~* "[\"'<>]") {
        return 403;
    }
    proxy_pass http://misp_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.