CWE-79
AllowedImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Abstraction: Base · Status: Stable
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
70945 vulnerabilities reference this CWE, most recent first.
CVE-2026-105116 (GCVE-0-2026-105116)
Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/OpenIdentityPlatform/OpenAM/se… | vendor-advisory |
| https://www.vulncheck.com/advisories/openam-befor… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| OpenIdentityPlatform | OpenAM |
Affected:
0 , < 16.1.3
(semver)
Unaffected: 16.1.3 (semver) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.openidentityplatform.openam/openam-server-only",
"product": "OpenAM",
"vendor": "OpenIdentityPlatform",
"versions": [
{
"lessThan": "16.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "16.1.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.openidentityplatform.openam/openam-federation-library",
"product": "OpenAM",
"vendor": "OpenIdentityPlatform",
"versions": [
{
"lessThan": "16.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "16.1.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.openidentityplatform.openam/openam-auth-saml2",
"product": "OpenAM",
"vendor": "OpenIdentityPlatform",
"versions": [
{
"lessThan": "16.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "16.1.3",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "santhreal"
},
{
"lang": "en",
"type": "finder",
"value": "maximthomas"
},
{
"lang": "en",
"type": "finder",
"value": "tsujiguchitky"
}
],
"datePublic": "2026-09-18T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T12:14:41.631Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-v796-mg6j-9c5m)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-v796-mg6j-9c5m"
},
{
"name": "VulnCheck Advisory: OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-latent-xss-in-saml-load-balancer-cookie-bounce-page"
}
],
"title": "OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105116",
"datePublished": "2026-10-03T12:14:41.631Z",
"dateReserved": "2026-10-03T12:04:36.964Z",
"dateUpdated": "2026-10-03T12:14:41.631Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105114 (GCVE-0-2026-105114)
Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/OpenIdentityPlatform/OpenAM/se… | vendor-advisory |
| https://www.vulncheck.com/advisories/openam-befor… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| OpenIdentityPlatform | OpenAM |
Affected:
0 , < 16.1.3
(semver)
Unaffected: 16.1.3 (semver) cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.openidentityplatform.openam/openam-oauth2",
"product": "OpenAM",
"vendor": "OpenIdentityPlatform",
"versions": [
{
"lessThan": "16.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "16.1.3",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Buggs777"
},
{
"lang": "en",
"type": "finder",
"value": "tsujiguchitky"
}
],
"datePublic": "2026-09-18T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T12:14:39.964Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-3m32-w9x3-vvq8)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-3m32-w9x3-vvq8"
},
{
"name": "VulnCheck Advisory: OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-reflected-xss-via-oauth2-authorization-error-page"
}
],
"title": "OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105114",
"datePublished": "2026-10-03T12:14:39.964Z",
"dateReserved": "2026-10-03T12:04:36.964Z",
"dateUpdated": "2026-10-03T12:14:39.964Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104907 (GCVE-0-2026-104907)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:51 – Updated: 2026-10-02 16:18| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/70ad174dd | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 15:50 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/70ad174dd.patch
048909e6f2d9… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
70ad174ddd43
|
fix: [security] Cast the remote tag id in the event preview | 048909e6f2d9… |
Fix summary
The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.
Patch summary
In app/View/Servers/preview_event.ctp, the expression h($tag['id']) inside the onclick attribute's JavaScript string was replaced with (int)$tag['id']. This changes the output from an HTML-escaped string to a strictly integer value, preventing any non-numeric characters from being injected into the inline script context.
CVSS rationale
AV:N - the attack originates from a remote linked server over the network. AC:L - the injection is straightforward (embed a quote in a tag ID). AT:N - no special timing or race conditions required. PR:L - the attacker must be a configured linked server, which requires some level of trust/access but not full admin. UI:A - the victim must actively view the event preview and interact with the tag element. VC/VI/VA:N - the MISP server itself is not compromised; the impact is in the victim's browser. SC:N - no meaningful confidentiality impact on the subsequent component is guaranteed. SI:L - the injected script can perform limited actions (redirect, read page data, submit forms) in the user's session. SA:N - no availability impact on the subsequent component.
Weakness rationale
- CWE-79 The tag ID is embedded in an inline JavaScript onclick handler where HTML escaping (h()) does not neutralize JavaScript string breakout characters. This is a classic case of improper output encoding for a JavaScript context, resulting in reflected XSS.
- CWE-116 The root cause is using HTML entity encoding (h()) in a context that requires JavaScript string escaping. The encoding mechanism is inappropriate for the output context, which is a sub-category of the XSS issue.
Attack pattern rationale
- CAPEC-1 The vulnerability is a reflected XSS where attacker-controlled data (a tag ID from a linked server) is injected into an inline JavaScript event handler without proper context-aware encoding. CAPEC-1 is the closest general match. The specific sub-technique is injection into a JavaScript string literal within an HTML attribute, which is not separately enumerated in CAPEC.
- CAPEC-126 The attacker exploits the fact that the single-quote character (or similar) is not properly handled when the tag ID is placed inside a JavaScript string within an HTML attribute. The HTML escaping does not account for the JavaScript string delimiter. This CAPEC captures the character-handling aspect of the flaw. Uncertainty: CAPEC-1 is more directly about XSS; CAPEC-126 is included as a supplementary mapping for the encoding mismatch.
Assumptions to verify
- The affected version boundary is inferred from the tag v2.5.48 with 28 commits after the fix; the exact first affected version is not stated in the patch.
- The attacker is assumed to be a linked/remote MISP server that can control tag IDs in events shared with the local instance; the exact trust model and authentication for linked servers is not detailed in the patch.
- CAPEC-126 is included as a supplementary mapping; the primary and most defensible mapping is CAPEC-1 (Cross Site Scripting).
- The CVSS PR:L assumes that being a linked server requires some form of authenticated or trusted relationship, but the exact privilege level is not specified in the patch.
- The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is listed as a tool credit, not a human remediation developer.
- The impact scope (SC/SI) is assessed conservatively; the actual XSS payload capability depends on the browser context and same-origin policy, which are not fully specified.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 11 | medium | 6 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (70ad174ddd438887687d40fc1e2e4e8b322a179e): fix: [security] Cast the remote tag id in the event preview",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/70ad174dd.patch"
],
"timestamp": "2026-09-24T21:53:31Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104907",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:17:59.477633Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:18:12.403Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Servers/preview_event"
],
"product": "MISP",
"programFiles": [
"app/View/Servers/preview_event.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- A linked/remote MISP server is configured and connected to the local instance.\u003c/p\u003e\u003cp\u003e- The linked server supplies a crafted tag ID in an event.\u003c/p\u003e\u003cp\u003e- An authenticated user views the event preview and interacts with the affected tag element.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Arbitrary JavaScript execution in the context of the viewing user\u0027s browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.\u003c/p\u003e\u003cp\u003eAffected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).\u003c/p\u003e"
}
],
"value": "MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.\n\nPreconditions:\n\n- A linked/remote MISP server is configured and connected to the local instance.\n\n- The linked server supplies a crafted tag ID in an event.\n\n- An authenticated user views the event preview and interacts with the affected tag element.\n\nImpact:\n\n- Arbitrary JavaScript execution in the context of the viewing user\u0027s browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.\n\nAffected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed)."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting"
}
]
},
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Exploiting Incorrectly Handled Special/Control Characters"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "LOW",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:50:34Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Cross-site Scripting (XSS)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-116",
"description": "CWE-116 Improper Encoding or Escaping of Output",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:51:34.565Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/70ad174dd"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters."
}
],
"title": "MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag v2.5.48 with 28 commits after the fix; the exact first affected version is not stated in the patch.",
"The attacker is assumed to be a linked/remote MISP server that can control tag IDs in events shared with the local instance; the exact trust model and authentication for linked servers is not detailed in the patch.",
"CAPEC-126 is included as a supplementary mapping; the primary and most defensible mapping is CAPEC-1 (Cross Site Scripting).",
"The CVSS PR:L assumes that being a linked server requires some form of authenticated or trusted relationship, but the exact privilege level is not specified in the patch.",
"The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is listed as a tool credit, not a human remediation developer.",
"The impact scope (SC/SI) is assessed conservatively; the actual XSS payload capability depends on the browser context and same-origin policy, which are not fully specified."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The vulnerability is a reflected XSS where attacker-controlled data (a tag ID from a linked server) is injected into an inline JavaScript event handler without proper context-aware encoding. CAPEC-1 is the closest general match. The specific sub-technique is injection into a JavaScript string literal within an HTML attribute, which is not separately enumerated in CAPEC."
},
{
"capecId": "CAPEC-126",
"rationale": "The attacker exploits the fact that the single-quote character (or similar) is not properly handled when the tag ID is placed inside a JavaScript string within an HTML attribute. The HTML escaping does not account for the JavaScript string delimiter. This CAPEC captures the character-handling aspect of the flaw. Uncertainty: CAPEC-1 is more directly about XSS; CAPEC-126 is included as a supplementary mapping for the encoding mismatch."
}
],
"commit": "70ad174ddd438887687d40fc1e2e4e8b322a179e",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N - the attack originates from a remote linked server over the network. AC:L - the injection is straightforward (embed a quote in a tag ID). AT:N - no special timing or race conditions required. PR:L - the attacker must be a configured linked server, which requires some level of trust/access but not full admin. UI:A - the victim must actively view the event preview and interact with the tag element. VC/VI/VA:N - the MISP server itself is not compromised; the impact is in the victim\u0027s browser. SC:N - no meaningful confidentiality impact on the subsequent component is guaranteed. SI:L - the injected script can perform limited actions (redirect, read page data, submit forms) in the user\u0027s session. SA:N - no availability impact on the subsequent component.",
"fixSummary": "The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.",
"generatedAt": "2026-10-02T15:50:34.593118Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "048909e6f2d91cc9e6f920e8416edc5f9f44410eba1becc15373378f46a221de",
"patchSummary": "In app/View/Servers/preview_event.ctp, the expression h($tag[\u0027id\u0027]) inside the onclick attribute\u0027s JavaScript string was replaced with (int)$tag[\u0027id\u0027]. This changes the output from an HTML-escaped string to a strictly integer value, preventing any non-numeric characters from being injected into the inline script context.",
"patchTruncated": false,
"patches": [
{
"commit": "70ad174ddd438887687d40fc1e2e4e8b322a179e",
"date": "Thu, 24 Sep 2026 23:53:31 +0200",
"patchSha256": "048909e6f2d91cc9e6f920e8416edc5f9f44410eba1becc15373378f46a221de",
"source": "https://github.com/MISP/MISP/commit/70ad174dd.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/70ad174dd.patch",
"subject": "fix: [security] Cast the remote tag id in the event preview"
}
],
"source": "https://github.com/MISP/MISP/commit/70ad174dd.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:50:34Z",
"version": "2.0.3"
},
"subject": "fix: [security] Cast the remote tag id in the event preview",
"tagVersionBoundary": {
"commits_after_fix": 28,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The tag ID is embedded in an inline JavaScript onclick handler where HTML escaping (h()) does not neutralize JavaScript string breakout characters. This is a classic case of improper output encoding for a JavaScript context, resulting in reflected XSS."
},
{
"cweId": "CWE-116",
"rationale": "The root cause is using HTML entity encoding (h()) in a context that requires JavaScript string escaping. The encoding mechanism is inappropriate for the output context, which is a sub-category of the XSS issue."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (70ad174ddd438887687d40fc1e2e4e8b322a179e): fix: [security] Cast the remote tag id in the event preview",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/70ad174dd.patch"
],
"timestamp": "2026-09-24T21:53:31Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20154"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104907",
"datePublished": "2026-10-02T15:51:34.565Z",
"dateReserved": "2026-10-02T15:51:32.541Z",
"dateUpdated": "2026-10-02T16:18:12.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104906 (GCVE-0-2026-104906)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:49 – Updated: 2026-10-02 16:17- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/1bed4ca0c | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 15:47 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/1bed4ca0c.patch
6f48e50f2a68… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
1bed4ca0c990
|
fix: [security] Escape the JSON shown in the generic JSON | 6f48e50f2a68… |
Fix summary
The fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector.
Patch summary
In app/View/Elements/genericElements/json.ctp, the sprintf call that builds the pre tag was changed from json_encode($json) to h(json_encode($json)). The h() function (CakePHP's HTML-encoding helper, equivalent to htmlspecialchars) now escapes angle brackets, ampersands, and quotes in the JSON output before it is placed inside the HTML pre element. One line changed, one file affected.
CVSS rationale
AV:N: The vulnerability is exploitable over the network via the MISP web interface. AC:L: No race conditions or special timing required; simply viewing the object triggers the XSS. AT:N: The malicious payload is already embedded in the TAXII object; no manipulation of the attack target is needed at exploit time. PR:L: The attacker needs a MISP account (or the ability to publish to a subscribed TAXII server) to place the payload. UI:A: The victim must actively open/view the TAXII object in the viewer. VC/VI/VA:N: The MISP server itself is not compromised; the impact is client-side. SC:H: An attacker can read session cookies, API tokens, and data visible in the MISP UI. SI:H: An attacker can perform actions as the authenticated user (create/modify objects, change settings). SA:N: No denial-of-service impact on the system.
Weakness rationale
- CWE-79 The patch directly addresses the failure to HTML-encode untrusted JSON data before embedding it in an HTML context. The h() wrapper is the canonical fix for CWE-79 in CakePHP applications. The data originates from external TAXII objects and is rendered without encoding, allowing script injection.
Attack pattern rationale
- CAPEC-66 The attack pattern involves injecting script-enabled content into a web page via untrusted data (TAXII object string properties) that is rendered without encoding. CAPEC-66 is the most specific CAPEC for XSS. The uncertainty is that the exact delivery mechanism (stored in a TAXII server vs. reflected) is not fully specified in the patch, but the core pattern of unencoded user-controlled data in an HTML context matches CAPEC-66 precisely.
Assumptions to verify
- The affected version boundary (< 2.5.48) is inferred from the tag_version_boundary metadata (v2.5.48, 29 commits after fix); the patch metadata does not explicitly state a fixed version.
- PR:L assumes the TAXII object viewer requires authenticated access to MISP; if the viewer is accessible without authentication, PR would be None.
- The CAPEC-66 mapping is the closest available pattern for XSS; the exact delivery vector (stored via TAXII server vs. reflected) is not fully specified in the patch, but the core unencoded-output pattern is unambiguous.
- The Co-Authored-By line references an AI assistant (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer.
- UI:A assumes the victim must actively navigate to and render the specific TAXII object; if the object is auto-loaded in a dashboard, UI could be None.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
8 | 11 | high | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (1bed4ca0c990a4c285e8caa1d7efd91fec43eaca): fix: [security] Escape the JSON shown in the generic JSON",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/1bed4ca0c.patch"
],
"timestamp": "2026-09-24T21:24:48Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104906",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:17:09.468515Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:17:21.730Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"TAXII object viewer",
"app/View/Elements/genericElements/json.ctp"
],
"product": "MISP",
"programFiles": [
"app/View/Elements/genericElements/json.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim\u0027s MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim\u0027s MISP session.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The victim must be an authenticated MISP user with access to the TAXII object viewer.\u003c/p\u003e\u003cp\u003e- The victim must open or view the crafted TAXII object.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\u003c/p\u003e\u003cp\u003e- Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface.\u003c/p\u003e\u003cp\u003e- Potential for performing actions on behalf of the authenticated user.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim\u0027s MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim\u0027s MISP session.\n\nPreconditions:\n\n- The victim must be an authenticated MISP user with access to the TAXII object viewer.\n\n- The victim must open or view the crafted TAXII object.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\n\n- Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface.\n\n- Potential for performing actions on behalf of the authenticated user.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-66",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-66 Cross Site Scripting (XSS)"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:47:29Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:49:32.948Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/1bed4ca0c"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector.\u003c/p\u003e"
}
],
"value": "The fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector."
}
],
"title": "MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary (\u003c 2.5.48) is inferred from the tag_version_boundary metadata (v2.5.48, 29 commits after fix); the patch metadata does not explicitly state a fixed version.",
"PR:L assumes the TAXII object viewer requires authenticated access to MISP; if the viewer is accessible without authentication, PR would be None.",
"The CAPEC-66 mapping is the closest available pattern for XSS; the exact delivery vector (stored via TAXII server vs. reflected) is not fully specified in the patch, but the core unencoded-output pattern is unambiguous.",
"The Co-Authored-By line references an AI assistant (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer.",
"UI:A assumes the victim must actively navigate to and render the specific TAXII object; if the object is auto-loaded in a dashboard, UI could be None."
],
"capecRationale": [
{
"capecId": "CAPEC-66",
"rationale": "The attack pattern involves injecting script-enabled content into a web page via untrusted data (TAXII object string properties) that is rendered without encoding. CAPEC-66 is the most specific CAPEC for XSS. The uncertainty is that the exact delivery mechanism (stored in a TAXII server vs. reflected) is not fully specified in the patch, but the core pattern of unencoded user-controlled data in an HTML context matches CAPEC-66 precisely."
}
],
"commit": "1bed4ca0c990a4c285e8caa1d7efd91fec43eaca",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N: The vulnerability is exploitable over the network via the MISP web interface. AC:L: No race conditions or special timing required; simply viewing the object triggers the XSS. AT:N: The malicious payload is already embedded in the TAXII object; no manipulation of the attack target is needed at exploit time. PR:L: The attacker needs a MISP account (or the ability to publish to a subscribed TAXII server) to place the payload. UI:A: The victim must actively open/view the TAXII object in the viewer. VC/VI/VA:N: The MISP server itself is not compromised; the impact is client-side. SC:H: An attacker can read session cookies, API tokens, and data visible in the MISP UI. SI:H: An attacker can perform actions as the authenticated user (create/modify objects, change settings). SA:N: No denial-of-service impact on the system.",
"fixSummary": "The fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector.",
"generatedAt": "2026-10-02T15:47:29.857932Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 8
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "6f48e50f2a682434a041678f85a824d0f37ffaf42dda6b0d664e756bc2c7d4b1",
"patchSummary": "In app/View/Elements/genericElements/json.ctp, the sprintf call that builds the pre tag was changed from json_encode($json) to h(json_encode($json)). The h() function (CakePHP\u0027s HTML-encoding helper, equivalent to htmlspecialchars) now escapes angle brackets, ampersands, and quotes in the JSON output before it is placed inside the HTML pre element. One line changed, one file affected.",
"patchTruncated": false,
"patches": [
{
"commit": "1bed4ca0c990a4c285e8caa1d7efd91fec43eaca",
"date": "Thu, 24 Sep 2026 23:24:48 +0200",
"patchSha256": "6f48e50f2a682434a041678f85a824d0f37ffaf42dda6b0d664e756bc2c7d4b1",
"source": "https://github.com/MISP/MISP/commit/1bed4ca0c.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/1bed4ca0c.patch",
"subject": "fix: [security] Escape the JSON shown in the generic JSON"
}
],
"source": "https://github.com/MISP/MISP/commit/1bed4ca0c.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:47:29Z",
"version": "2.0.3"
},
"subject": "fix: [security] Escape the JSON shown in the generic JSON",
"tagVersionBoundary": {
"commits_after_fix": 29,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The patch directly addresses the failure to HTML-encode untrusted JSON data before embedding it in an HTML context. The h() wrapper is the canonical fix for CWE-79 in CakePHP applications. The data originates from external TAXII objects and is rendered without encoding, allowing script injection."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (1bed4ca0c990a4c285e8caa1d7efd91fec43eaca): fix: [security] Escape the JSON shown in the generic JSON",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/1bed4ca0c.patch"
],
"timestamp": "2026-09-24T21:24:48Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20251"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104906",
"datePublished": "2026-10-02T15:49:32.948Z",
"dateReserved": "2026-10-02T15:49:31.457Z",
"dateUpdated": "2026-10-02T16:17:21.730Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104901 (GCVE-0-2026-104901)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:21 – Updated: 2026-10-02 16:15- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/bd5e80c84 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 15:17 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/bd5e80c84.patch
398814c5f528… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
bd5e80c84f0a
|
fix: [security] Treat the remote event id in the ID | 398814c5f528… |
Fix summary
The vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser.
Patch summary
In ServersController.php, the remote_event['id'] value is cast to (int) in two locations where it is stored in the remote_events array and where it is extracted from the API response. In app/View/Servers/id_translator.ctp, the h() escaping function is applied to remote_id in the anchor text and to both server_id and remote_id in the preview URL. In app/View/Themed/Overmind/Servers/id_translator.ctp, h() is applied to remote_id in the badge display and to server_id and remote_id in the preview link. An 'exception' key is also initialized to null in the first array construction for consistency.
CVSS rationale
AV:N: The attack originates from a remote linked server over the network. AC:L: No race conditions or special timing are required; the linked server simply returns a crafted ID. AT:N: No active user interaction is needed to set up the attack (the malicious server is already linked). PR:N: The attacker is the linked server itself and does not need credentials on the victim's instance. UI:A: The victim must actively navigate to the ID Translator page for the payload to execute. VC:N/VI:N/VA:N: The vulnerable component (MISP server) is not directly compromised; the impact is client-side. SC:L: A successful XSS can read cookies, session tokens, or page data in the victim's browser. SI:L: The attacker can modify the rendered page content. SA:N: No impact on the security authority of the system.
Weakness rationale
- CWE-79 The remote event ID returned by a linked server was rendered in HTML output without output encoding, allowing injection of arbitrary markup or script. The fix applies HTML escaping (h()) and integer casting, which is the canonical remediation for CWE-79.
Attack pattern rationale
- CAPEC-1 The closest CAPEC pattern is reflected XSS: data originating from an external source (the linked server's API response) is reflected into the rendered HTML page without encoding. The mapping is slightly imprecise because the data source is a server-to-server API response rather than a direct user-supplied request parameter, but the mechanism (untrusted data reflected into HTML) matches CAPEC-1 most closely among available patterns. CAPEC-120 (Persistent XSS) was considered but the data is not stored in the victim's database; it is fetched live from the remote server and rendered, making the reflected pattern a better fit.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 30 commits after fix); the exact first affected version is not specified in the patch.
- The CAPEC-1 mapping is the closest available pattern; the data source is a server-to-server API response rather than a direct HTTP request parameter, making the 'reflected' classification slightly imprecise.
- The attacker is assumed to be a configured linked MISP server; no evidence suggests the vulnerability is exploitable without a pre-existing server link.
- The UI:A rating assumes the victim must explicitly navigate to the ID Translator page; it is unclear whether any automated workflow could trigger this view without direct user action.
- The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (bd5e80c84f0ab853d88d14e14df9bd92786eb8f4): fix: [security] Treat the remote event id in the ID",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/bd5e80c84.patch"
],
"timestamp": "2026-09-24T21:24:11Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104901",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:15:35.943839Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:15:49.327Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"ServersController (idTranslator)",
"View/Servers/id_translator.ctp",
"View/Themed/Overmind/Servers/id_translator.ctp"
],
"product": "MISP",
"programFiles": [
"app/Controller/ServersController.php",
"app/View/Servers/id_translator.ctp",
"app/View/Themed/Overmind/Servers/id_translator.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output encoding.\u003c/p\u003e\u003cp\u003eA malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The victim must be an authenticated user of the host MISP instance.\u003c/p\u003e\u003cp\u003e- A linked server must be configured on the host instance.\u003c/p\u003e\u003cp\u003e- The victim must navigate to the ID Translator page for a given event.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output encoding.\n\nA malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks.\n\nPreconditions:\n\n- The victim must be an authenticated user of the host MISP instance.\n\n- A linked server must be configured on the host instance.\n\n- The victim must navigate to the ID Translator page for a given event.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 XSS - Reflected"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:17:39Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:21:53.492Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/bd5e80c84"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser."
}
],
"title": "MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 30 commits after fix); the exact first affected version is not specified in the patch.",
"The CAPEC-1 mapping is the closest available pattern; the data source is a server-to-server API response rather than a direct HTTP request parameter, making the \u0027reflected\u0027 classification slightly imprecise.",
"The attacker is assumed to be a configured linked MISP server; no evidence suggests the vulnerability is exploitable without a pre-existing server link.",
"The UI:A rating assumes the victim must explicitly navigate to the ID Translator page; it is unclear whether any automated workflow could trigger this view without direct user action.",
"The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The closest CAPEC pattern is reflected XSS: data originating from an external source (the linked server\u0027s API response) is reflected into the rendered HTML page without encoding. The mapping is slightly imprecise because the data source is a server-to-server API response rather than a direct user-supplied request parameter, but the mechanism (untrusted data reflected into HTML) matches CAPEC-1 most closely among available patterns. CAPEC-120 (Persistent XSS) was considered but the data is not stored in the victim\u0027s database; it is fetched live from the remote server and rendered, making the reflected pattern a better fit."
}
],
"commit": "bd5e80c84f0ab853d88d14e14df9bd92786eb8f4",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N: The attack originates from a remote linked server over the network. AC:L: No race conditions or special timing are required; the linked server simply returns a crafted ID. AT:N: No active user interaction is needed to set up the attack (the malicious server is already linked). PR:N: The attacker is the linked server itself and does not need credentials on the victim\u0027s instance. UI:A: The victim must actively navigate to the ID Translator page for the payload to execute. VC:N/VI:N/VA:N: The vulnerable component (MISP server) is not directly compromised; the impact is client-side. SC:L: A successful XSS can read cookies, session tokens, or page data in the victim\u0027s browser. SI:L: The attacker can modify the rendered page content. SA:N: No impact on the security authority of the system.",
"fixSummary": "The vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser.",
"generatedAt": "2026-10-02T15:17:39.791225Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "398814c5f528eb504bfc173c7ed3258a171d9f3feeca03d8ba4fff252d3a8c1f",
"patchSummary": "In ServersController.php, the remote_event[\u0027id\u0027] value is cast to (int) in two locations where it is stored in the remote_events array and where it is extracted from the API response. In app/View/Servers/id_translator.ctp, the h() escaping function is applied to remote_id in the anchor text and to both server_id and remote_id in the preview URL. In app/View/Themed/Overmind/Servers/id_translator.ctp, h() is applied to remote_id in the badge display and to server_id and remote_id in the preview link. An \u0027exception\u0027 key is also initialized to null in the first array construction for consistency.",
"patchTruncated": false,
"patches": [
{
"commit": "bd5e80c84f0ab853d88d14e14df9bd92786eb8f4",
"date": "Thu, 24 Sep 2026 23:24:11 +0200",
"patchSha256": "398814c5f528eb504bfc173c7ed3258a171d9f3feeca03d8ba4fff252d3a8c1f",
"source": "https://github.com/MISP/MISP/commit/bd5e80c84.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/bd5e80c84.patch",
"subject": "fix: [security] Treat the remote event id in the ID"
}
],
"source": "https://github.com/MISP/MISP/commit/bd5e80c84.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:17:39Z",
"version": "2.0.3"
},
"subject": "fix: [security] Treat the remote event id in the ID",
"tagVersionBoundary": {
"commits_after_fix": 30,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The remote event ID returned by a linked server was rendered in HTML output without output encoding, allowing injection of arbitrary markup or script. The fix applies HTML escaping (h()) and integer casting, which is the canonical remediation for CWE-79."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (bd5e80c84f0ab853d88d14e14df9bd92786eb8f4): fix: [security] Treat the remote event id in the ID",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/bd5e80c84.patch"
],
"timestamp": "2026-09-24T21:24:11Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20296"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104901",
"datePublished": "2026-10-02T15:21:53.492Z",
"dateReserved": "2026-10-02T15:21:46.840Z",
"dateUpdated": "2026-10-02T16:15:49.327Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104900 (GCVE-0-2026-104900)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:16 – Updated: 2026-10-02 16:15- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/2a2981a27 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 11:32 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/2a2981a27.patch
3c8a41f55b53… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
2a2981a27bd0
|
fix: [security] Escape the value of the count index field | 3c8a41f55b53… |
Fix summary
The vulnerability is remediated by applying HTML entity encoding to the count field value before it is rendered in the view template. This ensures that any HTML or script markup contained in the value from a remote server is neutralized and displayed as inert text rather than being interpreted by the browser.
Patch summary
In the CakePHP view template file app/View/Elements/genericElements/IndexTable/Fields/count.ctp, the assignment of $fieldValue was changed from a raw Hash::extract() call to one wrapped in the h() helper function (CakePHP's HTML-encoding utility). This single-line change ensures the extracted value is HTML-entity-encoded before being used in the template output, preventing injection of markup through the event identifier from a linked server.
CVSS rationale
AV:N - exploitation occurs over the network via a linked MISP server. AC:L - the attacker only needs to craft an event ID with HTML/JS; no race conditions or complex timing. AT:N - the malicious data is stored in the linked server; no active attack is needed at exploitation time. PR:L - the attacker needs low-privilege access to a linked MISP server to create/modify an event. UI:N - the victim only needs to view the remote event preview index page; no special interaction. VC/VI/VA:N - no direct impact on the MISP server's own confidentiality, integrity, or availability. SC:L - XSS allows reading some data (cookies, DOM) in the victim's browser. SI:L - attacker can modify what the victim sees in the browser. SA:N - no impact on security authority of the victim's system.
Weakness rationale
- CWE-79 The patch adds HTML encoding (h() function) to a value that was previously rendered raw in an HTML context. The commit message explicitly states the value was printed raw, allowing markup injection. This is a textbook stored/reflected XSS due to missing output encoding.
Attack pattern rationale
- CAPEC-1 The attack pattern involves injecting script or markup into a web page through a data field (event ID from a linked server) that is rendered without encoding. CAPEC-1 is the closest standard mapping for XSS via untrusted data rendered in a browser context. The specific vector here is a linked MISP server supplying crafted data, which is a variant of the general XSS injection pattern. No more specific CAPEC precisely captures the 'trusted remote server as injection vector' nuance, so CAPEC-1 is the best available match.
Assumptions to verify
- The affected version boundary is inferred from the nearest tag v2.5.48 with 31 commits after the fix; the exact last affected version is not explicitly stated in the patch.
- PR:L assumes the attacker needs at least low-privilege access to a linked MISP server to create or modify an event; if no authentication is required on the linked server, PR could be None.
- The CAPEC-1 mapping is the closest standard pattern; no CAPEC specifically covers 'XSS via data from a trusted remote server' as a distinct pattern.
- The Co-Authored-By line references an AI assistant (Claude Opus 5.5); it is listed as a tool credit rather than a human remediation developer.
- The commit date (24 Sep 2026) is in the future relative to typical CVE timelines; this is taken at face value from the patch metadata.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (2a2981a27bd06bfd6fa37866db1911637d52538c): fix: [security] Escape the value of the count index field",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/2a2981a27.patch"
],
"timestamp": "2026-09-24T20:20:05Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104900",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:14:50.253586Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:15:09.284Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Remote Event Preview Index Table (count field)"
],
"product": "MISP",
"programFiles": [
"app/View/Elements/genericElements/IndexTable/Fields/count.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated link URL but rendered the field value without HTML encoding. An attacker with the ability to create or modify events on a linked (remote) MISP server could craft an event identifier containing HTML or JavaScript markup. When a user on the local MISP instance views the remote event preview index, the unescaped value is rendered directly in the browser, allowing arbitrary script execution in the victim\u0027s session.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- A linked/remote MISP server is configured and connected to the local instance.\u003c/p\u003e\u003cp\u003e- The attacker has sufficient access on the linked server to create or modify an event with a crafted identifier.\u003c/p\u003e\u003cp\u003e- A victim user on the local instance views the remote event preview index page.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary JavaScript in the context of the MISP web application.\u003c/p\u003e\u003cp\u003e- Potential session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated link URL but rendered the field value without HTML encoding. An attacker with the ability to create or modify events on a linked (remote) MISP server could craft an event identifier containing HTML or JavaScript markup. When a user on the local MISP instance views the remote event preview index, the unescaped value is rendered directly in the browser, allowing arbitrary script execution in the victim\u0027s session.\n\nPreconditions:\n\n- A linked/remote MISP server is configured and connected to the local instance.\n\n- The attacker has sufficient access on the linked server to create or modify an event with a crafted identifier.\n\n- A victim user on the local instance views the remote event preview index page.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the context of the MISP web application.\n\n- Potential session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T11:32:45Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:16:27.485Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/2a2981a27"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by applying HTML entity encoding to the count field value before it is rendered in the view template. This ensures that any HTML or script markup contained in the value from a remote server is neutralized and displayed as inert text rather than being interpreted by the browser.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by applying HTML entity encoding to the count field value before it is rendered in the view template. This ensures that any HTML or script markup contained in the value from a remote server is neutralized and displayed as inert text rather than being interpreted by the browser."
}
],
"title": "MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the nearest tag v2.5.48 with 31 commits after the fix; the exact last affected version is not explicitly stated in the patch.",
"PR:L assumes the attacker needs at least low-privilege access to a linked MISP server to create or modify an event; if no authentication is required on the linked server, PR could be None.",
"The CAPEC-1 mapping is the closest standard pattern; no CAPEC specifically covers \u0027XSS via data from a trusted remote server\u0027 as a distinct pattern.",
"The Co-Authored-By line references an AI assistant (Claude Opus 5.5); it is listed as a tool credit rather than a human remediation developer.",
"The commit date (24 Sep 2026) is in the future relative to typical CVE timelines; this is taken at face value from the patch metadata."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The attack pattern involves injecting script or markup into a web page through a data field (event ID from a linked server) that is rendered without encoding. CAPEC-1 is the closest standard mapping for XSS via untrusted data rendered in a browser context. The specific vector here is a linked MISP server supplying crafted data, which is a variant of the general XSS injection pattern. No more specific CAPEC precisely captures the \u0027trusted remote server as injection vector\u0027 nuance, so CAPEC-1 is the best available match."
}
],
"commit": "2a2981a27bd06bfd6fa37866db1911637d52538c",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N - exploitation occurs over the network via a linked MISP server. AC:L - the attacker only needs to craft an event ID with HTML/JS; no race conditions or complex timing. AT:N - the malicious data is stored in the linked server; no active attack is needed at exploitation time. PR:L - the attacker needs low-privilege access to a linked MISP server to create/modify an event. UI:N - the victim only needs to view the remote event preview index page; no special interaction. VC/VI/VA:N - no direct impact on the MISP server\u0027s own confidentiality, integrity, or availability. SC:L - XSS allows reading some data (cookies, DOM) in the victim\u0027s browser. SI:L - attacker can modify what the victim sees in the browser. SA:N - no impact on security authority of the victim\u0027s system.",
"fixSummary": "The vulnerability is remediated by applying HTML entity encoding to the count field value before it is rendered in the view template. This ensures that any HTML or script markup contained in the value from a remote server is neutralized and displayed as inert text rather than being interpreted by the browser.",
"generatedAt": "2026-10-01T11:32:45.636394Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "3c8a41f55b536b1beaab7797cf106c1ef8f72ec83417cf60660c60171f939a5e",
"patchSummary": "In the CakePHP view template file app/View/Elements/genericElements/IndexTable/Fields/count.ctp, the assignment of $fieldValue was changed from a raw Hash::extract() call to one wrapped in the h() helper function (CakePHP\u0027s HTML-encoding utility). This single-line change ensures the extracted value is HTML-entity-encoded before being used in the template output, preventing injection of markup through the event identifier from a linked server.",
"patchTruncated": false,
"patches": [
{
"commit": "2a2981a27bd06bfd6fa37866db1911637d52538c",
"date": "Thu, 24 Sep 2026 22:20:05 +0200",
"patchSha256": "3c8a41f55b536b1beaab7797cf106c1ef8f72ec83417cf60660c60171f939a5e",
"source": "https://github.com/MISP/MISP/commit/2a2981a27.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/2a2981a27.patch",
"subject": "fix: [security] Escape the value of the count index field"
}
],
"source": "https://github.com/MISP/MISP/commit/2a2981a27.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T11:32:45Z",
"version": "2.0.3"
},
"subject": "fix: [security] Escape the value of the count index field",
"tagVersionBoundary": {
"commits_after_fix": 31,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The patch adds HTML encoding (h() function) to a value that was previously rendered raw in an HTML context. The commit message explicitly states the value was printed raw, allowing markup injection. This is a textbook stored/reflected XSS due to missing output encoding."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (2a2981a27bd06bfd6fa37866db1911637d52538c): fix: [security] Escape the value of the count index field",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/2a2981a27.patch"
],
"timestamp": "2026-09-24T20:20:05Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20230"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104900",
"datePublished": "2026-10-02T15:16:27.485Z",
"dateReserved": "2026-10-02T15:16:25.316Z",
"dateUpdated": "2026-10-02T16:15:09.284Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104847 (GCVE-0-2026-104847)
Vulnerability from cvelistv5 – Published: 2026-10-02 16:02 – Updated: 2026-10-02 16:57- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/ProseMirror/prosemirror-view/s… | x_refsource_CONFIRM |
| https://github.com/ProseMirror/prosemirror-view/c… | x_refsource_MISC |
| https://github.com/ProseMirror/prosemirror-view/c… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| ProseMirror | prosemirror-view |
Affected:
< 1.42.3
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104847",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:57:07.727132Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:57:44.659Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "prosemirror-view",
"vendor": "ProseMirror",
"versions": [
{
"status": "affected",
"version": "\u003c 1.42.3"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ProseMirror\u0027s view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema attribute validation. When a user pastes the crafted HTML into an editor, the unvalidated context attributes can construct content that executes attacker-controlled JavaScript in the browser window containing the editor. This issue is fixed in version 1.42.3."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:02:42.475Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/ProseMirror/prosemirror-view/security/advisories/GHSA-c8x8-7fp4-3x9w",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/ProseMirror/prosemirror-view/security/advisories/GHSA-c8x8-7fp4-3x9w"
},
{
"name": "https://github.com/ProseMirror/prosemirror-view/security/advisories/GHSA-c8x8-7fp4-3x9w",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ProseMirror/prosemirror-view/security/advisories/GHSA-c8x8-7fp4-3x9w"
},
{
"name": "https://github.com/ProseMirror/prosemirror-view/commit/20dc0a911a79f8fc6640dbbea5e7d68d3c4784b7",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ProseMirror/prosemirror-view/commit/20dc0a911a79f8fc6640dbbea5e7d68d3c4784b7"
},
{
"name": "https://github.com/ProseMirror/prosemirror-view/commit/2e91a612bbc1248e55b4f6061fc93fe459f977c1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/ProseMirror/prosemirror-view/commit/2e91a612bbc1248e55b4f6061fc93fe459f977c1"
}
],
"source": {
"advisory": "GHSA-c8x8-7fp4-3x9w",
"discovery": "UNKNOWN"
},
"title": "ProseMirror: XSS vulnerability in prosemirror-view\u0027s paste handling"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-104847",
"datePublished": "2026-10-02T16:02:42.475Z",
"dateReserved": "2026-10-02T14:38:43.243Z",
"dateUpdated": "2026-10-02T16:57:44.659Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104612 (GCVE-0-2026-104612)
Vulnerability from cvelistv5 – Published: 2026-10-02 12:45 – Updated: 2026-10-02 12:45 X_Freeware| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412921 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412921/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-104612 | third-party-advisory |
| https://vuldb.com/submit/963426 | third-party-advisory |
| https://github.com/Jack-MRJ/srms-vulnerabilities/… | broken-linkexploit |
| https://www.sourcecodester.com/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| SourceCodester | Student Result Management System |
Affected:
1.0
cpe:2.3:a:sourcecodester:student_result_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:sourcecodester:student_result_management_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Announcement Module"
],
"product": "Student Result Management System",
"vendor": "SourceCodester",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "yuanchao (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file script/academic/core/new_announcement.php of the component Announcement Module. The manipulation of the argument title/announcement results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Cross Site Scripting",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "Code Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T12:45:16.441Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412921 | SourceCodester Student Result Management System Announcement new_announcement.php cross site scripting",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412921"
},
{
"name": "VDB-412921 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412921/cti"
},
{
"name": "CVE-2026-104612 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-104612"
},
{
"name": "Submit #963426 | SourceCodester SRMS - Student Result Management System 1.0 Cross Site Scripting (CWE-79)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/963426"
},
{
"tags": [
"broken-link",
"exploit"
],
"url": "https://github.com/Jack-MRJ/srms-vulnerabilities/blob/main/SRMS_Stored_XSS_VulDB_CVE_Report_v1.pdf"
},
{
"tags": [
"product"
],
"url": "https://www.sourcecodester.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-10-02T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-02T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-02T06:20:59.000Z",
"value": "VulDB entry last update"
}
],
"title": "SourceCodester Student Result Management System Announcement new_announcement.php cross site scripting",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-104612",
"datePublished": "2026-10-02T12:45:16.441Z",
"dateReserved": "2026-10-02T04:15:45.284Z",
"dateUpdated": "2026-10-02T12:45:16.441Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104479 (GCVE-0-2026-104479)
Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/mindstellar/shopclass/commit/c… | patch |
| https://github.com/mindstellar/shopclass | product |
| https://www.vulncheck.com/advisories/shopclass-be… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| mindstellar | shopclass |
Affected:
0 , < 6.2.0
(semver)
Unaffected: 6.2.0 (semver) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "shopclass",
"repo": "https://github.com/mindstellar/shopclass",
"vendor": "mindstellar",
"versions": [
{
"lessThan": "6.2.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Islomjon Tursunov"
}
],
"datePublic": "2026-08-27T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T23:28:48.624Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/mindstellar/shopclass/commit/c196f70906522c9b9172c24f1b42cd0a02357422"
},
{
"tags": [
"product"
],
"url": "https://github.com/mindstellar/shopclass"
},
{
"name": "VulnCheck Advisory: Shopclass before 6.2.0 Stored XSS via Listing Description Field",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/shopclass-before-6.2.0-stored-xss-via-listing-description-field"
}
],
"title": "Shopclass before 6.2.0 Stored XSS via Listing Description Field",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104479",
"datePublished": "2026-10-02T23:28:48.624Z",
"dateReserved": "2026-10-02T00:55:58.388Z",
"dateUpdated": "2026-10-02T23:28:48.624Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104477 (GCVE-0-2026-104477)
Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/showdownjs/showdown/commit/4fb… | patch |
| https://github.com/showdownjs/showdown | product |
| https://www.vulncheck.com/advisories/showdown-thr… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| showdownjs | showdown |
Affected:
0 , ≤ 2.1.0
(semver)
cpe:2.3:a:showdownjs:showdown:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/showdown",
"product": "showdown",
"vendor": "showdownjs",
"versions": [
{
"lessThanOrEqual": "2.1.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:showdownjs:showdown:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Muhammad Sobirov"
}
],
"datePublic": "2026-06-27T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T23:28:47.414Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/showdownjs/showdown/commit/4fb992cd26631c108ec0410342630c80207ec7c6"
},
{
"tags": [
"product"
],
"url": "https://github.com/showdownjs/showdown"
},
{
"name": "VulnCheck Advisory: Showdown through 2.1.0 XSS via unescaped quote in href and src attributes",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/showdown-through-2.1.0-xss-via-unescaped-quote-in-href-and-src-attributes"
}
],
"title": "Showdown through 2.1.0 XSS via unescaped quote in href and src attributes",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104477",
"datePublished": "2026-10-02T23:28:47.414Z",
"dateReserved": "2026-10-02T00:55:58.388Z",
"dateUpdated": "2026-10-02T23:28:47.414Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation MIT-4
Strategy: Libraries or Frameworks
- Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].
- Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and Apache Wicket.
Mitigation
- Understand the context in which your data will be used and the encoding that will be expected. This is especially important when transmitting data between different components, or when generating outputs that can contain multiple encodings at the same time, such as web pages or multi-part mail messages. Study all expected communication protocols and data representations to determine the required encoding strategies.
- For any data that will be output to another web page, especially any data that was received from external inputs, use the appropriate encoding on all non-alphanumeric characters.
- Parts of the same output document may require different encodings, which will vary depending on whether the output is in the:
- etc. Note that HTML Entity Encoding is only appropriate for the HTML body.
- Consult the XSS Prevention Cheat Sheet [REF-724] for more details on the types of encoding and escaping that are needed.
- HTML body
- Element attributes (such as src="XYZ")
- URIs
- JavaScript sections
- Cascading Style Sheets and style property
Mitigation MIT-6
Strategy: Attack Surface Reduction
Understand all the potential areas where untrusted inputs can enter your software: parameters or arguments, cookies, anything read from the network, environment variables, reverse DNS lookups, query results, request headers, URL components, e-mail, files, filenames, databases, and any external systems that provide data to the application. Remember that such inputs may be obtained indirectly through API calls.
Mitigation MIT-15
For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
Mitigation MIT-27
Strategy: Parameterization
If available, use structured mechanisms that automatically enforce the separation between data and code. These mechanisms may be able to provide the relevant quoting, encoding, and validation automatically, instead of relying on the developer to provide this capability at every point where output is generated.
Mitigation MIT-30.1
Strategy: Output Encoding
- Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or automatically inferring which encoding is being used, which can be erroneous. When the encodings are inconsistent, the downstream component might treat some character or byte sequences as special, even if they are not special in the original encoding. Attackers might then be able to exploit this discrepancy and conduct injection attacks; they even might be able to bypass protection mechanisms that assume the original encoding is also being used by the downstream component.
- The problem of inconsistent output encodings often arises in web pages. If an encoding is not specified in an HTTP header, web browsers often guess about which encoding is being used. This can open up the browser to subtle XSS attacks.
Mitigation MIT-43
With Struts, write all data from form beans with the bean's filter attribute set to true.
Mitigation MIT-31
Strategy: Attack Surface Reduction
To help mitigate XSS attacks against the user's session cookie, set the session cookie to be HttpOnly. In browsers that support the HttpOnly feature (such as more recent versions of Internet Explorer and Firefox), this attribute can prevent the user's session cookie from being accessible to malicious client-side scripts that use document.cookie. This is not a complete solution, since HttpOnly is not supported by all browsers. More importantly, XmlHttpRequest and other powerful browser technologies provide read access to HTTP headers, including the Set-Cookie header in which the HttpOnly flag is set.
Mitigation MIT-5
Strategy: Input Validation
- Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does.
- When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue."
- Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.
- When dynamically constructing web pages, use stringent allowlists that limit the character set based on the expected value of the parameter in the request. All input should be validated and cleansed, not just parameters that the user is supposed to specify, but all data in the request, including hidden fields, cookies, headers, the URL itself, and so forth. A common mistake that leads to continuing XSS vulnerabilities is to validate only fields that are expected to be redisplayed by the site. It is common to see data from the request that is reflected by the application server or the application that the development team did not anticipate. Also, a field that is not currently reflected may be used by a future developer. Therefore, validating ALL parts of the HTTP request is recommended.
- Note that proper output encoding, escaping, and quoting is the most effective solution for preventing XSS, although input validation may provide some defense-in-depth. This is because it effectively limits what will appear in output. Input validation will not always prevent XSS, especially if you are required to support free-form text fields that could contain arbitrary characters. For example, in a chat application, the heart emoticon ("<3") would likely pass the validation step, since it is commonly used. However, it cannot be directly inserted into the web page because it contains the "<" character, which would need to be escaped or otherwise handled. In this case, stripping the "<" might reduce the risk of XSS, but it would produce incorrect behavior because the emoticon would not be recorded. This might seem to be a minor inconvenience, but it would be more important in a mathematical forum that wants to represent inequalities.
- Even if you make a mistake in your validation (such as forgetting one out of 100 input fields), appropriate encoding is still likely to protect you from injection-based attacks. As long as it is not done in isolation, input validation is still a useful technique, since it may significantly reduce your attack surface, allow you to detect some attacks, and provide other security benefits that proper encoding does not address.
- Ensure that you perform input validation at well-defined interfaces within the application. This will help protect the application even if a component is reused or moved elsewhere.
Mitigation MIT-21
Strategy: Enforcement by Conversion
When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.
Mitigation MIT-29
Strategy: Firewall
Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].
Mitigation MIT-16
Strategy: Environment Hardening
When using PHP, configure the application so that it does not use register_globals. During implementation, develop the application so that it does not rely on this feature, but be wary of implementing a register_globals emulation that is subject to weaknesses such as CWE-95, CWE-621, and similar issues.
CAPEC-209: XSS Using MIME Type Mismatch
An adversary creates a file with scripting content but where the specified MIME type of the file is such that scripting is not expected. The adversary tricks the victim into accessing a URL that responds with the script file. Some browsers will detect that the specified MIME type of the file does not match the actual type of its content and will automatically switch to using an interpreter for the real content type. If the browser does not invoke script filters before doing this, the adversary's script may run on the target unsanitized, possibly revealing the victim's cookies or executing arbitrary script in their browser.
CAPEC-588: DOM-Based XSS
This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is inserted into the client-side HTML being parsed by a web browser. Content served by a vulnerable web application includes script code used to manipulate the Document Object Model (DOM). This script code either does not properly validate input, or does not perform proper output encoding, thus creating an opportunity for an adversary to inject a malicious script launch a XSS attack. A key distinction between other XSS attacks and DOM-based attacks is that in other XSS attacks, the malicious script runs when the vulnerable web page is initially loaded, while a DOM-based attack executes sometime after the page loads. Another distinction of DOM-based attacks is that in some cases, the malicious script is never sent to the vulnerable web server at all. An attack like this is guaranteed to bypass any server-side filtering attempts to protect users.
CAPEC-591: Reflected XSS
This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is "reflected" off a vulnerable web application and then executed by a victim's browser. The process starts with an adversary delivering a malicious script to a victim and convincing the victim to send the script to the vulnerable web application.
CAPEC-592: Stored XSS
An adversary utilizes a form of Cross-site Scripting (XSS) where a malicious script is persistently "stored" within the data storage of a vulnerable web application as valid input.
CAPEC-63: Cross-Site Scripting (XSS)
An adversary embeds malicious scripts in content that will be served to web browsers. The goal of the attack is for the target software, the client-side browser, to execute the script with the users' privilege level. An attack of this type exploits a programs' vulnerabilities that are brought on by allowing remote hosts to execute code and scripts. Web browsers, for example, have some simple security controls in place, but if a remote attacker is allowed to execute scripts (through injecting them in to user-generated content like bulletin boards) then these controls may be bypassed. Further, these attacks are very difficult for an end user to detect.
CAPEC-85: AJAX Footprinting
This attack utilizes the frequent client-server roundtrips in Ajax conversation to scan a system. While Ajax does not open up new vulnerabilities per se, it does optimize them from an attacker point of view. A common first step for an attacker is to footprint the target environment to understand what attacks will work. Since footprinting relies on enumeration, the conversational pattern of rapid, multiple requests and responses that are typical in Ajax applications enable an attacker to look for many vulnerabilities, well-known ports, network locations and so on. The knowledge gained through Ajax fingerprinting can be used to support other attacks, such as XSS.