Skip to main content
Vulnerability Database/CVE-2026-95665

CVE-2026-95665: MISP Event REST Search XSS Vulnerability

CVE-2026-95665 is a reflected XSS flaw in MISP that allows attackers to execute arbitrary JavaScript through crafted URLs in the event REST search export form. This post explains its impact, affected themes, and mitigation steps.

Published:

CVE-2026-95665 Overview

CVE-2026-95665 is a reflected cross-site scripting (XSS) vulnerability in MISP, the open-source threat intelligence platform. The flaw resides in the event REST search export confirmation form, specifically in the app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp view template. The template renders a URL-supplied event ID list into a single-quoted JavaScript string using PHP's json_encode() without hex-encoding flags. Because json_encode() does not escape single quotes by default, an attacker can break out of the string literal and execute arbitrary JavaScript. The vulnerability affects the Default and UiBeta themes. The Overmind theme is not affected because it renders the value through an escaped data attribute.

Critical Impact

Attackers can execute arbitrary JavaScript in an authenticated MISP user's browser session, enabling session hijacking, unauthorized actions, and exfiltration of threat intelligence data.

Affected Products

  • MISP (Malware Information Sharing Platform) — Default theme
  • MISP (Malware Information Sharing Platform) — UiBeta theme
  • Vulnerable component: app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp

Discovery Timeline

  • 2026-09-22 - CVE-2026-95665 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-95665

Vulnerability Analysis

The vulnerability is a reflected XSS classified under [CWE-79]. The flaw lives in the redirectToExportResult() JavaScript function embedded in the export confirmation view. The template concatenates the JSON-encoded event ID list from the URL directly into a single-quoted string literal. PHP's json_encode() escapes double quotes, backslashes, and forward slashes but leaves single quotes untouched unless the JSON_HEX_APOS flag is set.

An attacker who crafts a URL containing a single-quote character in the event ID list can terminate the JavaScript string literal early and inject arbitrary script. The payload executes in the authenticated victim's session on the MISP web application. Impact includes session hijacking, unauthorized submissions on behalf of the user, and exfiltration of sensitive threat intelligence visible to that account. Exploitation requires user interaction: the victim must be authenticated to MISP and must click or navigate to the attacker-supplied link.

Root Cause

The root cause is improper output encoding for the JavaScript string context. The developer used json_encode() without context-appropriate escaping flags and delimited the resulting output with single quotes in the HTML template. json_encode() produces output safe for embedding inside double-quoted JavaScript strings, but not inside single-quoted string literals unless JSON_HEX_APOS is applied.

Attack Vector

The attack vector is network-based and requires user interaction. An unauthenticated attacker crafts a URL targeting the vulnerable MISP endpoint with a malicious event ID list containing a single quote followed by JavaScript. The attacker delivers the URL via phishing, social engineering, or an embedded link on an external site. When an authenticated MISP user visits the URL, the injected JavaScript executes in their browser under the MISP origin.

text
// Security patch in app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp
 ?>
 <script>
     function redirectToExportResult() {
-        var idListStr = '<?= json_encode($idList) ?>'
+        var idListStr = '<?= json_encode($idList, JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_QUOT | JSON_HEX_AMP) ?>'
         var returnFormat = $('#EventReturnFormat').val()
         window.location = '<?= $baseurl ?>/events/restSearchExport/' + idListStr + '/' + returnFormat
     }
// Source: https://github.com/MISP/MISP/commit/ad4ff238d

The fix adds four JSON encoding flags: JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP. These hex-encode <, >, ', ", and & so the output is safe in any HTML or JavaScript string context.

Detection Methods for CVE-2026-95665

Indicators of Compromise

  • HTTP requests to MISP event REST search export endpoints containing URL-encoded single quotes (%27) or raw single quotes in the event ID list parameter.
  • Web server or proxy logs showing referrers from untrusted external domains preceding requests to /events/restSearchExport/ or the confirmation form URL.
  • Unusual JavaScript payload strings such as <script>, onerror=, or fetch( in URL parameters targeting the confirmation form view.

Detection Strategies

  • Deploy web application firewall (WAF) rules that inspect MISP request URIs for single-quote characters and script-like payloads in event ID parameters.
  • Review MISP access logs for anomalous request patterns to the export confirmation form path, particularly requests originating from external referrers.
  • Correlate authenticated user session events with outbound requests to unfamiliar domains that could indicate session token exfiltration.

Monitoring Recommendations

  • Enable detailed request logging on the MISP reverse proxy or web server and forward logs to a centralized SIEM for pattern-based analysis.
  • Monitor MISP audit logs for unexpected API actions, event edits, or data exports tied to individual user accounts shortly after link-click events.
  • Alert on Content-Security-Policy violation reports if CSP is enforced on the MISP deployment.

How to Mitigate CVE-2026-95665

Immediate Actions Required

  • Apply the upstream MISP patch from commit ad4ff238d to update the vulnerable view template.
  • Instruct MISP users to avoid clicking on MISP-related URLs received from untrusted sources until patching is complete.
  • Rotate MISP API keys and force session re-authentication for any users suspected of clicking crafted links prior to remediation.

Patch Information

The MISP maintainers fixed the issue by adding JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_QUOT | JSON_HEX_AMP flags to the json_encode() call in app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp. Administrators should pull the latest MISP release containing the upstream commit and redeploy the application.

Workarounds

  • Switch affected deployments to the Overmind theme, which passes the value through an escaped data attribute and is not vulnerable to this specific sink.
  • Implement a strict Content-Security-Policy header that disallows inline script execution to limit exploitability while patch deployment is scheduled.
  • Restrict access to the MISP web interface to trusted networks or VPN clients to reduce the attack surface for phishing-delivered links.
bash
# Update MISP to the patched revision
cd /var/www/MISP
sudo -u www-data git fetch origin
sudo -u www-data git checkout <patched-tag-or-commit>
sudo -u www-data git submodule update --init --recursive
sudo systemctl restart apache2

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.