Find a vulnerability
Search criteria
190 vulnerabilities by misp
CVE-2026-104914 (GCVE-0-2026-104914)
Vulnerability from cvelistv5 – Published: 2026-10-02 16:09 – Updated: 2026-10-02 16:09qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 16:06 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/bd81c23cf.patch
9673ee1d4db2… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
bd81c23cf2ac
|
fix: [security] Show soft-deleted attributes only to the | 9673ee1d4db2… |
Fix summary
The fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user's organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic.
Patch summary
Two code paths were modified:1. Event.php (fetchPaginatedAttributes): When the deleted filter is active and the user lacks perm_sync, an additional subquery condition is appended requiring the event owner's org_id to match the user's org_id. The original blanket deleted=0 or deleted=1 condition is replaced with an OR/AND structure that permits non-deleted attributes for all users but restricts deleted attributes to the owning org.2. MispAttribute.php (fetchAttributes): In the deleted='only' branch, when the user lacks perm_sync, an additional AND condition Event.org_id = user.org_id is added to the query conditions, scoping results to the user's own organization.
CVSS rationale
AV:N: The vulnerability is exploitable over the network via the MISP web API. AC:L: Exploitation requires only a standard query with the deleted-attribute filter; no race conditions or complex setup. AT:N: No special attack requirements. PR:L: An authenticated user with at least read access to an event owned by another organization is required. UI:N: No victim interaction needed; the data is returned in the API response. VC:L: Confidentiality impact is limited to soft-deleted attributes (a subset of event data) from other organizations; not all data is exposed. VI:N, VA:N: No integrity or availability impact on the vulnerable component. SC:N, SI:N, SA:N: No impact on subsequent components.
Weakness rationale
- CWE-862 The attribute search and paginated view code paths were missing the authorization check that restricts soft-deleted attribute visibility to the owning organization. The event view had this check, but the attribute-level query paths did not, allowing any user with event visibility to retrieve soft-deleted attributes from other organizations.
- CWE-284 More broadly, the application failed to enforce proper access control boundaries between organizations when serving soft-deleted attribute data through specific query endpoints, resulting in cross-organizational information disclosure.
Attack pattern rationale
- CAPEC-126 This CAPEC describes leveraging legitimate application code paths to access or manipulate data beyond intended permissions. The attacker uses the legitimate attribute search and paginated view endpoints (executable code paths) to retrieve soft-deleted attributes from other organizations. The mapping is imperfect because CAPEC-126 emphasizes data alteration, whereas this vulnerability is purely an information disclosure. However, among available CAPEC patterns, this is the closest match for exploiting a legitimate code path to bypass intended access restrictions. No CAPEC specifically covers 'information disclosure via missing authorization in a query endpoint' with greater precision.
Assumptions to verify
- The exact fixed version is not specified in the patch metadata; the fix commit is 37 commits after the v2.5.48 tag, so the fixed release is post-2.5.48 but the exact version number is unknown.
- PR:L assumes the attacker needs at least read access to an event owned by another organization; if MISP deployments restrict cross-org event visibility more tightly, the effective privilege requirement may be higher.
- CAPEC-126 is the closest available mapping but is not a perfect fit; the vulnerability is an information disclosure via missing authorization rather than data alteration.
- VC:L assumes the exposure is limited to soft-deleted attributes (a subset of event data) and does not include active attributes or full event metadata.
- The patch does not specify whether this affects all MISP deployments or only multi-organization configurations; the CVSS assumes a multi-org deployment where cross-org visibility is possible.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (bd81c23cf2aced3c72766369dc813612edd52509): fix: [security] Show soft-deleted attributes only to the",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/bd81c23cf.patch"
],
"timestamp": "2026-09-24T11:57:21Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"app/Model/Event.php",
"app/Model/MispAttribute.php"
],
"product": "MISP",
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
},
{
"lang": "en",
"type": "reporter",
"value": "elhoim"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints.\u003c/p\u003e\u003cp\u003eWhen a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated MISP user with at least read access to an event owned by another organization.\u003c/p\u003e\u003cp\u003e- The user issues a query for deleted attributes (search or paginated view with the deleted filter).\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility.\u003c/p\u003e\u003cp\u003eAffected versions: MISP versions prior to v2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints.\n\nWhen a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction.\n\nPreconditions:\n\n- An authenticated MISP user with at least read access to an event owned by another organization.\n\n- The user issues a query for deleted attributes (search or paginated view with the deleted filter).\n\nImpact:\n\n- Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility.\n\nAffected versions: MISP versions prior to v2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Leverage Executable Code to Alter Data"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T16:06:38Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "CWE-284 Improper Access Control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:09:40.333Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/bd81c23cf"
},
{
"url": "https://github.com/elhoim"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user\u0027s organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic.\u003c/p\u003e"
}
],
"value": "The fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user\u0027s organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic."
}
],
"title": "MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The exact fixed version is not specified in the patch metadata; the fix commit is 37 commits after the v2.5.48 tag, so the fixed release is post-2.5.48 but the exact version number is unknown.",
"PR:L assumes the attacker needs at least read access to an event owned by another organization; if MISP deployments restrict cross-org event visibility more tightly, the effective privilege requirement may be higher.",
"CAPEC-126 is the closest available mapping but is not a perfect fit; the vulnerability is an information disclosure via missing authorization rather than data alteration.",
"VC:L assumes the exposure is limited to soft-deleted attributes (a subset of event data) and does not include active attributes or full event metadata.",
"The patch does not specify whether this affects all MISP deployments or only multi-organization configurations; the CVSS assumes a multi-org deployment where cross-org visibility is possible."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "This CAPEC describes leveraging legitimate application code paths to access or manipulate data beyond intended permissions. The attacker uses the legitimate attribute search and paginated view endpoints (executable code paths) to retrieve soft-deleted attributes from other organizations. The mapping is imperfect because CAPEC-126 emphasizes data alteration, whereas this vulnerability is purely an information disclosure. However, among available CAPEC patterns, this is the closest match for exploiting a legitimate code path to bypass intended access restrictions. No CAPEC specifically covers \u0027information disclosure via missing authorization in a query endpoint\u0027 with greater precision."
}
],
"commit": "bd81c23cf2aced3c72766369dc813612edd52509",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
},
{
"lang": "en",
"type": "reporter",
"value": "elhoim"
}
],
"cvssRationale": "AV:N: The vulnerability is exploitable over the network via the MISP web API. AC:L: Exploitation requires only a standard query with the deleted-attribute filter; no race conditions or complex setup. AT:N: No special attack requirements. PR:L: An authenticated user with at least read access to an event owned by another organization is required. UI:N: No victim interaction needed; the data is returned in the API response. VC:L: Confidentiality impact is limited to soft-deleted attributes (a subset of event data) from other organizations; not all data is exposed. VI:N, VA:N: No integrity or availability impact on the vulnerable component. SC:N, SI:N, SA:N: No impact on subsequent components.",
"fixSummary": "The fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user\u0027s organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic.",
"generatedAt": "2026-10-02T16:06:38.209479Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "9673ee1d4db26b032b6e3a2632315d5353cd2718c9b809a5296d28a0002a3722",
"patchSummary": "Two code paths were modified:1. Event.php (fetchPaginatedAttributes): When the deleted filter is active and the user lacks perm_sync, an additional subquery condition is appended requiring the event owner\u0027s org_id to match the user\u0027s org_id. The original blanket deleted=0 or deleted=1 condition is replaced with an OR/AND structure that permits non-deleted attributes for all users but restricts deleted attributes to the owning org.2. MispAttribute.php (fetchAttributes): In the deleted=\u0027only\u0027 branch, when the user lacks perm_sync, an additional AND condition Event.org_id = user.org_id is added to the query conditions, scoping results to the user\u0027s own organization.",
"patchTruncated": false,
"patches": [
{
"commit": "bd81c23cf2aced3c72766369dc813612edd52509",
"date": "Thu, 24 Sep 2026 13:57:21 +0200",
"patchSha256": "9673ee1d4db26b032b6e3a2632315d5353cd2718c9b809a5296d28a0002a3722",
"source": "https://github.com/MISP/MISP/commit/bd81c23cf.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/bd81c23cf.patch",
"subject": "fix: [security] Show soft-deleted attributes only to the"
}
],
"source": "https://github.com/MISP/MISP/commit/bd81c23cf.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T16:06:38Z",
"version": "2.0.3"
},
"subject": "fix: [security] Show soft-deleted attributes only to the",
"tagVersionBoundary": {
"commits_after_fix": 37,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-862",
"rationale": "The attribute search and paginated view code paths were missing the authorization check that restricts soft-deleted attribute visibility to the owning organization. The event view had this check, but the attribute-level query paths did not, allowing any user with event visibility to retrieve soft-deleted attributes from other organizations."
},
{
"cweId": "CWE-284",
"rationale": "More broadly, the application failed to enforce proper access control boundaries between organizations when serving soft-deleted attribute data through specific query endpoints, resulting in cross-organizational information disclosure."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (bd81c23cf2aced3c72766369dc813612edd52509): fix: [security] Show soft-deleted attributes only to the",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/bd81c23cf.patch"
],
"timestamp": "2026-09-24T11:57:21Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20248"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104914",
"datePublished": "2026-10-02T16:09:40.333Z",
"dateReserved": "2026-10-02T16:09:36.435Z",
"dateUpdated": "2026-10-02T16:09:40.333Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104912 (GCVE-0-2026-104912)
Vulnerability from cvelistv5 – Published: 2026-10-02 16:04 – Updated: 2026-10-03 15:52| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/100235bd9 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 16:02 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/100235bd9.patch
a38b683420d9… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
100235bd99b9
|
fix: [security] Check correlations against the live event ACL | a38b683420d9… |
Fix summary
The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.
Patch summary
In DefaultCorrelationBehavior.php: (1) runGetRelatedAttributes now builds query conditions that include the live attribute ACL (buildConditions) for non-site-admin users, and ensures Event and Object are contained in the query for proper filtering; (2) after fetching related attributes, Event and Object sub-objects are unset from each result; (3) fetchRelatedEventIds now passes its results through a new __filterVisibleEventIds method that queries the Event model with createEventConditions to verify each event ID is still visible to the user; (4) the new __filterVisibleEventIds method returns the event IDs unchanged for site admins or empty lists, otherwise filters against the live event ACL.
CVSS rationale
Network vector: MISP is a web application accessible over the network. Low complexity: the attacker simply performs a normal attribute search that triggers correlations; no race condition or special setup is needed. No attack requirements: the stale correlation row exists naturally after any event restriction. Low privileges: the attacker needs an authenticated account with read access to at least one event. No user interaction: the attacker initiates the search themselves. High vulnerability-component confidentiality impact: full attribute values and event metadata of restricted events are exposed. No integrity or availability impact on the vulnerable or subsequent components.
Weakness rationale
- CWE-862 The correlation lookup path failed to enforce the current (live) authorization state of the target events and attributes. Access was granted based on a stale snapshot rather than the actual ACL, effectively missing the authorization check for restricted events.
- CWE-284 The access control decision relied on outdated data (the distribution columns copied onto the correlation row) that did not reflect the current published/sharing-group state of the event, leading to improper access control.
Attack pattern rationale
- CAPEC-114 The authorization state used for correlation lookups was incorrectly adjusted (stale) relative to the actual event ACL. An attacker with a legitimate account could exploit this misalignment to access data beyond their intended privilege scope. This is the closest CAPEC pattern; the exact mechanism is a stale authorization snapshot rather than a classic privilege-escalation primitive, so the mapping is approximate.
Assumptions to verify
- The affected version boundary (< 2.5.48) is inferred from the tag_version_boundary metadata (v2.5.48, 38 commits after fix); the exact first affected version is not stated in the patch.
- CVSS PR:L assumes the attacker needs a standard authenticated MISP account with read access to at least one event; no evidence supports a lower or higher privilege requirement.
- CAPEC-114 is the closest available pattern; the actual mechanism is a stale authorization snapshot rather than a classic privilege-escalation vector, so the mapping is approximate.
- The patch does not specify whether the vulnerability requires the event to have been restricted after correlation creation, or whether other state changes (e.g., sharing group modification) also trigger the issue; the commit message mentions 'restricted' as the primary scenario.
- No public exploit or PoC is referenced; exploitation status is assumed to be 'none'.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (100235bd99b9f57a5a09976412d54e2001d2e0c4): fix: [security] Check correlations against the live event ACL",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/100235bd9.patch"
],
"timestamp": "2026-09-24T10:12:56Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104912",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:48:11.201423Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:52:55.841Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"app/Model/Behavior/DefaultCorrelationBehavior.php"
],
"product": "MISP",
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
},
{
"lang": "en",
"type": "reporter",
"value": "elhoim"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.\u003c/p\u003e\u003cp\u003eBecause the correlation row\u0027s distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated user with at least read access to some events in the instance.\u003c/p\u003e\u003cp\u003e- The existence of correlations between events, at least one of which has been restricted after the correlation was created.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.\u003c/p\u003e\u003cp\u003eAffected versions: MISP prior to v2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.\n\nBecause the correlation row\u0027s distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.\n\nPreconditions:\n\n- An authenticated user with at least read access to some events in the instance.\n\n- The existence of correlations between events, at least one of which has been restricted after the correlation was created.\n\nImpact:\n\n- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.\n\nAffected versions: MISP prior to v2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-114",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-114 Exploiting Incorrectly Adjusted Privileges"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T16:02:40Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "CWE-284 Improper Access Control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:04:50.580Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/100235bd9"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.\u003c/p\u003e"
}
],
"value": "The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage."
}
],
"title": "MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary (\u003c 2.5.48) is inferred from the tag_version_boundary metadata (v2.5.48, 38 commits after fix); the exact first affected version is not stated in the patch.",
"CVSS PR:L assumes the attacker needs a standard authenticated MISP account with read access to at least one event; no evidence supports a lower or higher privilege requirement.",
"CAPEC-114 is the closest available pattern; the actual mechanism is a stale authorization snapshot rather than a classic privilege-escalation vector, so the mapping is approximate.",
"The patch does not specify whether the vulnerability requires the event to have been restricted after correlation creation, or whether other state changes (e.g., sharing group modification) also trigger the issue; the commit message mentions \u0027restricted\u0027 as the primary scenario.",
"No public exploit or PoC is referenced; exploitation status is assumed to be \u0027none\u0027."
],
"capecRationale": [
{
"capecId": "CAPEC-114",
"rationale": "The authorization state used for correlation lookups was incorrectly adjusted (stale) relative to the actual event ACL. An attacker with a legitimate account could exploit this misalignment to access data beyond their intended privilege scope. This is the closest CAPEC pattern; the exact mechanism is a stale authorization snapshot rather than a classic privilege-escalation primitive, so the mapping is approximate."
}
],
"commit": "100235bd99b9f57a5a09976412d54e2001d2e0c4",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
},
{
"lang": "en",
"type": "reporter",
"value": "elhoim"
}
],
"cvssRationale": "Network vector: MISP is a web application accessible over the network. Low complexity: the attacker simply performs a normal attribute search that triggers correlations; no race condition or special setup is needed. No attack requirements: the stale correlation row exists naturally after any event restriction. Low privileges: the attacker needs an authenticated account with read access to at least one event. No user interaction: the attacker initiates the search themselves. High vulnerability-component confidentiality impact: full attribute values and event metadata of restricted events are exposed. No integrity or availability impact on the vulnerable or subsequent components.",
"fixSummary": "The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.",
"generatedAt": "2026-10-02T16:02:40.166976Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "a38b683420d93ff26d461badf81e0524bbd9618dd3dd6f187a994f5c5b47f23d",
"patchSummary": "In DefaultCorrelationBehavior.php: (1) runGetRelatedAttributes now builds query conditions that include the live attribute ACL (buildConditions) for non-site-admin users, and ensures Event and Object are contained in the query for proper filtering; (2) after fetching related attributes, Event and Object sub-objects are unset from each result; (3) fetchRelatedEventIds now passes its results through a new __filterVisibleEventIds method that queries the Event model with createEventConditions to verify each event ID is still visible to the user; (4) the new __filterVisibleEventIds method returns the event IDs unchanged for site admins or empty lists, otherwise filters against the live event ACL.",
"patchTruncated": false,
"patches": [
{
"commit": "100235bd99b9f57a5a09976412d54e2001d2e0c4",
"date": "Thu, 24 Sep 2026 12:12:56 +0200",
"patchSha256": "a38b683420d93ff26d461badf81e0524bbd9618dd3dd6f187a994f5c5b47f23d",
"source": "https://github.com/MISP/MISP/commit/100235bd9.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/100235bd9.patch",
"subject": "fix: [security] Check correlations against the live event ACL"
}
],
"source": "https://github.com/MISP/MISP/commit/100235bd9.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T16:02:40Z",
"version": "2.0.3"
},
"subject": "fix: [security] Check correlations against the live event ACL",
"tagVersionBoundary": {
"commits_after_fix": 38,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-862",
"rationale": "The correlation lookup path failed to enforce the current (live) authorization state of the target events and attributes. Access was granted based on a stale snapshot rather than the actual ACL, effectively missing the authorization check for restricted events."
},
{
"cweId": "CWE-284",
"rationale": "The access control decision relied on outdated data (the distribution columns copied onto the correlation row) that did not reflect the current published/sharing-group state of the event, leading to improper access control."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (100235bd99b9f57a5a09976412d54e2001d2e0c4): fix: [security] Check correlations against the live event ACL",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/100235bd9.patch"
],
"timestamp": "2026-09-24T10:12:56Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20312"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104912",
"datePublished": "2026-10-02T16:04:50.580Z",
"dateReserved": "2026-10-02T16:04:47.753Z",
"dateUpdated": "2026-10-03T15:52:55.841Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104910 (GCVE-0-2026-104910)
Vulnerability from cvelistv5 – Published: 2026-10-02 16:01 – Updated: 2026-10-03 15:52| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/2ffa97f05 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 15:59 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/2ffa97f05.patch
c315cbcd2cad… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
2ffa97f0526c
|
fix: [security] Scope the related event list to what the | c315cbcd2cad… |
Fix summary
The fix enforces proper per-event authorization on the related events query by applying the user's full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list.
Patch summary
In EventsController.php (viewRelatedEvents) and Event.php (getRelatedEvents), the query that fetches related event metadata previously used only Event.id IN (relatedEventIds) as the condition. The patch replaces this with a call to createEventConditions($user), which builds the full set of authorization conditions (published flag, distribution, sharing group), and then adds the Event.id filter on top. The stale comment claiming ACL was enforced via the correlation table was removed. Two files changed, 8 insertions, 9 deletions.
CVSS rationale
AV:N: MISP is a network-accessible web application. AC:L: An authenticated user simply requests the related events endpoint; no race condition or complex manipulation is needed. AT:N: No attack-target manipulation required. PR:L: Requires a low-privilege authenticated user with access to at least one event. UI:N: No user interaction needed. VC:L: Disclosure is limited to event metadata (title, date, correlation counts), not full event content or attributes. VI:N, VA:N: No integrity or availability impact. SC:N, SI:N, SA:N: No secondary impacts on other systems. The overall score reflects a low-severity information disclosure requiring authentication.
Weakness rationale
- CWE-862 The related events query did not apply the caller's per-event authorization checks (published status, distribution, sharing group). The system relied on a stale snapshot in the correlation table instead of re-validating access, effectively omitting the authorization step for the returned events.
- CWE-285 Even though some authorization existed (via the correlation table snapshot), it was based on outdated data and lacked the published flag check, making the authorization decision incorrect for events whose access parameters had changed or that were unpublished.
Attack pattern rationale
- CAPEC-126 The attacker leverages the trusted correlation relationship stored in the correlation table. The system treated the correlation entry as a sufficient authorization basis, but the snapshot data was stale and incomplete (missing published flag), allowing access to event metadata the caller should not see. This is the closest CAPEC to the pattern of relying on a trusted data source that does not reflect current authorization state. Uncertainty: no CAPEC perfectly describes 'stale authorization snapshot in a join table'; CAPEC-126 is the best available match.
Assumptions to verify
- The tag_version_boundary (v2.5.48, 50 commits after fix) is used as an approximate upper bound for affected versions; exact version boundaries are not explicitly stated in the patch metadata.
- PR:L assumes the attacker needs only a basic authenticated MISP account with access to at least one event; higher-privilege roles may be required depending on deployment configuration, but the patch does not specify this.
- VC:L assumes the disclosed metadata (event titles, dates, correlation counts) constitutes a low confidentiality impact; in highly sensitive threat-intelligence environments the impact could be rated higher.
- CAPEC-126 is the closest available mapping; no CAPEC precisely describes authorization bypass via a stale snapshot in a correlation/join table.
- The 'published' flag and distribution/sharing group checks are assumed to be the primary authorization mechanisms in MISP's event model, based on the commit message and patch context.
- No public exploit or active exploitation is assumed; the patch does not reference any CVE, advisory, or exploitation evidence.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 11 | medium | 6 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (2ffa97f0526cd6579b91a4dea560f6246ecbe108): fix: [security] Scope the related event list to what the",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/2ffa97f05.patch"
],
"timestamp": "2026-09-22T13:14:32Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104910",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:48:33.673589Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:52:56.095Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"EventsController (viewRelatedEvents)",
"Event model (getRelatedEvents)"
],
"product": "MISP",
"programFiles": [
"app/Controller/EventsController.php",
"app/Model/Event.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Wenhao Wu"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller\u0027s access rights against each related event.\u003c/p\u003e\u003cp\u003eThe correlation table stores a snapshot of the event\u0027s distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open\u2014because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded\u2014were still returned with their metadata (title, date, correlating value counts).\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated user with access to at least one event in MISP.\u003c/p\u003e\u003cp\u003e- The existence of correlation entries linking that event to other events the user should not be able to view.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access.\u003c/p\u003e\u003cp\u003e- Potential reconnaissance of threat-intelligence event names and timelines across sharing groups.\u003c/p\u003e\u003cp\u003eAffected: MISP versions prior to the fix commit (2ffa97f05).\u003c/p\u003e"
}
],
"value": "MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller\u0027s access rights against each related event.\n\nThe correlation table stores a snapshot of the event\u0027s distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open\u2014because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded\u2014were still returned with their metadata (title, date, correlating value counts).\n\nPreconditions:\n\n- An authenticated user with access to at least one event in MISP.\n\n- The existence of correlation entries linking that event to other events the user should not be able to view.\n\nImpact:\n\n- Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access.\n\n- Potential reconnaissance of threat-intelligence event names and timelines across sharing groups.\n\nAffected: MISP versions prior to the fix commit (2ffa97f05)."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Leverage Trusted Relationship"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:59:27Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285 Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:01:32.781Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/2ffa97f05"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix enforces proper per-event authorization on the related events query by applying the user\u0027s full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list.\u003c/p\u003e"
}
],
"value": "The fix enforces proper per-event authorization on the related events query by applying the user\u0027s full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list."
}
],
"title": "MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The tag_version_boundary (v2.5.48, 50 commits after fix) is used as an approximate upper bound for affected versions; exact version boundaries are not explicitly stated in the patch metadata.",
"PR:L assumes the attacker needs only a basic authenticated MISP account with access to at least one event; higher-privilege roles may be required depending on deployment configuration, but the patch does not specify this.",
"VC:L assumes the disclosed metadata (event titles, dates, correlation counts) constitutes a low confidentiality impact; in highly sensitive threat-intelligence environments the impact could be rated higher.",
"CAPEC-126 is the closest available mapping; no CAPEC precisely describes authorization bypass via a stale snapshot in a correlation/join table.",
"The \u0027published\u0027 flag and distribution/sharing group checks are assumed to be the primary authorization mechanisms in MISP\u0027s event model, based on the commit message and patch context.",
"No public exploit or active exploitation is assumed; the patch does not reference any CVE, advisory, or exploitation evidence."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The attacker leverages the trusted correlation relationship stored in the correlation table. The system treated the correlation entry as a sufficient authorization basis, but the snapshot data was stale and incomplete (missing published flag), allowing access to event metadata the caller should not see. This is the closest CAPEC to the pattern of relying on a trusted data source that does not reflect current authorization state. Uncertainty: no CAPEC perfectly describes \u0027stale authorization snapshot in a join table\u0027; CAPEC-126 is the best available match."
}
],
"commit": "2ffa97f0526cd6579b91a4dea560f6246ecbe108",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Wenhao Wu"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5 (1M context)"
}
],
"cvssRationale": "AV:N: MISP is a network-accessible web application. AC:L: An authenticated user simply requests the related events endpoint; no race condition or complex manipulation is needed. AT:N: No attack-target manipulation required. PR:L: Requires a low-privilege authenticated user with access to at least one event. UI:N: No user interaction needed. VC:L: Disclosure is limited to event metadata (title, date, correlation counts), not full event content or attributes. VI:N, VA:N: No integrity or availability impact. SC:N, SI:N, SA:N: No secondary impacts on other systems. The overall score reflects a low-severity information disclosure requiring authentication.",
"fixSummary": "The fix enforces proper per-event authorization on the related events query by applying the user\u0027s full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list.",
"generatedAt": "2026-10-02T15:59:27.212571Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "c315cbcd2cad3e0a5886680a4c6a903d9ed5f3fe3893670f74786cea77a56eb3",
"patchSummary": "In EventsController.php (viewRelatedEvents) and Event.php (getRelatedEvents), the query that fetches related event metadata previously used only Event.id IN (relatedEventIds) as the condition. The patch replaces this with a call to createEventConditions($user), which builds the full set of authorization conditions (published flag, distribution, sharing group), and then adds the Event.id filter on top. The stale comment claiming ACL was enforced via the correlation table was removed. Two files changed, 8 insertions, 9 deletions.",
"patchTruncated": false,
"patches": [
{
"commit": "2ffa97f0526cd6579b91a4dea560f6246ecbe108",
"date": "Tue, 22 Sep 2026 15:14:32 +0200",
"patchSha256": "c315cbcd2cad3e0a5886680a4c6a903d9ed5f3fe3893670f74786cea77a56eb3",
"source": "https://github.com/MISP/MISP/commit/2ffa97f05.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/2ffa97f05.patch",
"subject": "fix: [security] Scope the related event list to what the"
}
],
"source": "https://github.com/MISP/MISP/commit/2ffa97f05.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:59:27Z",
"version": "2.0.3"
},
"subject": "fix: [security] Scope the related event list to what the",
"tagVersionBoundary": {
"commits_after_fix": 50,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-862",
"rationale": "The related events query did not apply the caller\u0027s per-event authorization checks (published status, distribution, sharing group). The system relied on a stale snapshot in the correlation table instead of re-validating access, effectively omitting the authorization step for the returned events."
},
{
"cweId": "CWE-285",
"rationale": "Even though some authorization existed (via the correlation table snapshot), it was based on outdated data and lacked the published flag check, making the authorization decision incorrect for events whose access parameters had changed or that were unpublished."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (2ffa97f0526cd6579b91a4dea560f6246ecbe108): fix: [security] Scope the related event list to what the",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/2ffa97f05.patch"
],
"timestamp": "2026-09-22T13:14:32Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20165"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104910",
"datePublished": "2026-10-02T16:01:32.781Z",
"dateReserved": "2026-10-02T16:01:26.599Z",
"dateUpdated": "2026-10-03T15:52:56.095Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104908 (GCVE-0-2026-104908)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:56 – Updated: 2026-10-02 16:19| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/70e319e4b | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 15:55 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/70e319e4b.patch
2ea9ae3603b6… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
70e319e4b9db
|
fix: [security] Imported decaying models belong to the | 2ea9ae3603b6… |
Fix summary
The import handler now builds the model record from an explicit allow-list of permitted fields (name, parameters, description, ref, formula, version, enabled, all_orgs) using array_intersect_key, discarding any unlisted keys including nested model objects. The organisation identifier and default flag are set unconditionally after filtering. The save operation is preceded by an explicit create() call and the data is wrapped in the proper model key, preventing the ORM from interpreting attacker-supplied nested keys as separate model attributes.
Patch summary
In DecayingModelController::import(), the previous logic of unsetting id/uuid and pinning org_id/default on the flat array was replaced with an allow-list approach: array_intersect_key against a fixed set of importable fields, followed by explicit assignment of org_id from the authenticated user and default=0. A DecayingModel::create() call was added before save, and the save payload is now wrapped as array('DecayingModel' => $model) to bind the data to the correct model context. A regression test (DecayingModelImportOwnership) was added that verifies a nested DecayingModel key with a foreign id, org_id, and default=1 cannot overwrite or reassign an existing model.
CVSS rationale
AV:N - MISP is a network-accessible web application. AC:L - the attack requires only crafting a JSON payload with a nested key; no race condition or complex timing is needed. AT:N - no in-transit tampering required. PR:L - requires an authenticated user with perm_decaying, a low-privilege role. UI:N - no victim interaction needed. VC:N - no confidentiality impact; the attacker does not read data they cannot already access. VI:H - high integrity impact: an existing model belonging to another organisation can be overwritten in place, its ownership reassigned, or its default flag set, altering scoring for other users. VA:N - no availability impact. SC/SI/SA:N - the impact is confined to the MISP instance itself (same component); no secondary component is affected. Scope is not changed because both the vulnerable and impacted components are the MISP application and its data store.
Weakness rationale
- CWE-915 The import endpoint accepted user-supplied data and saved it without restricting which object attributes could be set. A nested model key allowed the attacker to modify the primary key, organisation, and default flag of a record, which are attributes that should be controlled exclusively by the application. This is a classic mass-assignment / improper dynamic attribute modification issue.
- CWE-285 The application failed to enforce that the imported model belongs to the caller's organisation. A user with only perm_decaying could modify records owned by other organisations, indicating an authorization boundary was not enforced on the object being written.
Attack pattern rationale
- CAPEC-13 The attacker tampers with the import request parameters by injecting a nested DecayingModel key containing unauthorized fields (id, org_id, default) that the application's top-level stripping did not filter. This is a direct form of parameter tampering where extra or modified parameters in the request bypass the intended input validation. The mapping is a close fit because the attack vector is manipulation of request parameters rather than a separate injection or protocol-level attack.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 21 commits after fix); the patch metadata does not explicitly state a fixed version string, so '< 2.5.48' is an analyst inference.
- The CAPEC-13 mapping is the closest available pattern; the attack is specifically a mass-assignment bypass via a nested model key rather than a generic parameter tampering, but no CAPEC entry precisely describes ORM-level mass assignment through nested keys.
- CVSS PR:L assumes perm_decaying is a low-privilege role available to many users; if it requires elevated privileges the score would be lower.
- The Co-Authored-By line references an AI assistant (Claude Opus 5); it is recorded as a tool credit, not a human remediation developer.
- No evidence of active exploitation or public PoC was found in the patch; SSVCE exploitation is set to 'none'.
- The patch does not specify authentication requirements beyond perm_decaying; it is assumed this is a standard MISP role rather than an admin-level permission.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | high | 6 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (70e319e4b9dbbeca173befce2340eedf9d86f1b0): fix: [security] Imported decaying models belong to the",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/70e319e4b.patch"
],
"timestamp": "2026-09-25T12:22:03Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104908",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:18:57.561492Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:19:17.687Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"DecayingModelController"
],
"product": "MISP",
"programFiles": [
"app/Controller/DecayingModelController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user\u0027s organisation, with the default flag forced to off.\u003c/p\u003e\u003cp\u003eHowever, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership.\u003c/p\u003e\u003cp\u003e- A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users.\u003c/p\u003e\u003cp\u003e- A user could reassign a model\u0027s organisation to an arbitrary value.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- Authenticated user with decaying-model permission (perm_decaying).\u003c/p\u003e\u003cp\u003e- Network access to the MISP instance.\u003c/p\u003e\u003cp\u003eAffected: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user\u0027s organisation, with the default flag forced to off.\n\nHowever, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation.\n\nImpact:\n\n- A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership.\n\n- A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users.\n\n- A user could reassign a model\u0027s organisation to an arbitrary value.\n\nPreconditions:\n\n- Authenticated user with decaying-model permission (perm_decaying).\n\n- Network access to the MISP instance.\n\nAffected: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-13",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-13 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:55:12Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285 Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:56:13.969Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/70e319e4b"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe import handler now builds the model record from an explicit allow-list of permitted fields (name, parameters, description, ref, formula, version, enabled, all_orgs) using array_intersect_key, discarding any unlisted keys including nested model objects. The organisation identifier and default flag are set unconditionally after filtering. The save operation is preceded by an explicit create() call and the data is wrapped in the proper model key, preventing the ORM from interpreting attacker-supplied nested keys as separate model attributes.\u003c/p\u003e"
}
],
"value": "The import handler now builds the model record from an explicit allow-list of permitted fields (name, parameters, description, ref, formula, version, enabled, all_orgs) using array_intersect_key, discarding any unlisted keys including nested model objects. The organisation identifier and default flag are set unconditionally after filtering. The save operation is preceded by an explicit create() call and the data is wrapped in the proper model key, preventing the ORM from interpreting attacker-supplied nested keys as separate model attributes."
}
],
"title": "MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 21 commits after fix); the patch metadata does not explicitly state a fixed version string, so \u0027\u003c 2.5.48\u0027 is an analyst inference.",
"The CAPEC-13 mapping is the closest available pattern; the attack is specifically a mass-assignment bypass via a nested model key rather than a generic parameter tampering, but no CAPEC entry precisely describes ORM-level mass assignment through nested keys.",
"CVSS PR:L assumes perm_decaying is a low-privilege role available to many users; if it requires elevated privileges the score would be lower.",
"The Co-Authored-By line references an AI assistant (Claude Opus 5); it is recorded as a tool credit, not a human remediation developer.",
"No evidence of active exploitation or public PoC was found in the patch; SSVCE exploitation is set to \u0027none\u0027.",
"The patch does not specify authentication requirements beyond perm_decaying; it is assumed this is a standard MISP role rather than an admin-level permission."
],
"capecRationale": [
{
"capecId": "CAPEC-13",
"rationale": "The attacker tampers with the import request parameters by injecting a nested DecayingModel key containing unauthorized fields (id, org_id, default) that the application\u0027s top-level stripping did not filter. This is a direct form of parameter tampering where extra or modified parameters in the request bypass the intended input validation. The mapping is a close fit because the attack vector is manipulation of request parameters rather than a separate injection or protocol-level attack."
}
],
"commit": "70e319e4b9dbbeca173befce2340eedf9d86f1b0",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"cvssRationale": "AV:N - MISP is a network-accessible web application. AC:L - the attack requires only crafting a JSON payload with a nested key; no race condition or complex timing is needed. AT:N - no in-transit tampering required. PR:L - requires an authenticated user with perm_decaying, a low-privilege role. UI:N - no victim interaction needed. VC:N - no confidentiality impact; the attacker does not read data they cannot already access. VI:H - high integrity impact: an existing model belonging to another organisation can be overwritten in place, its ownership reassigned, or its default flag set, altering scoring for other users. VA:N - no availability impact. SC/SI/SA:N - the impact is confined to the MISP instance itself (same component); no secondary component is affected. Scope is not changed because both the vulnerable and impacted components are the MISP application and its data store.",
"fixSummary": "The import handler now builds the model record from an explicit allow-list of permitted fields (name, parameters, description, ref, formula, version, enabled, all_orgs) using array_intersect_key, discarding any unlisted keys including nested model objects. The organisation identifier and default flag are set unconditionally after filtering. The save operation is preceded by an explicit create() call and the data is wrapped in the proper model key, preventing the ORM from interpreting attacker-supplied nested keys as separate model attributes.",
"generatedAt": "2026-10-02T15:55:12.256144Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 6,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "2ea9ae3603b60db40cddef05bf41462c4b235652ccd53d6e8a5596006232e59d",
"patchSummary": "In DecayingModelController::import(), the previous logic of unsetting id/uuid and pinning org_id/default on the flat array was replaced with an allow-list approach: array_intersect_key against a fixed set of importable fields, followed by explicit assignment of org_id from the authenticated user and default=0. A DecayingModel::create() call was added before save, and the save payload is now wrapped as array(\u0027DecayingModel\u0027 =\u003e $model) to bind the data to the correct model context. A regression test (DecayingModelImportOwnership) was added that verifies a nested DecayingModel key with a foreign id, org_id, and default=1 cannot overwrite or reassign an existing model.",
"patchTruncated": false,
"patches": [
{
"commit": "70e319e4b9dbbeca173befce2340eedf9d86f1b0",
"date": "Fri, 25 Sep 2026 14:22:03 +0200",
"patchSha256": "2ea9ae3603b60db40cddef05bf41462c4b235652ccd53d6e8a5596006232e59d",
"source": "https://github.com/MISP/MISP/commit/70e319e4b.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/70e319e4b.patch",
"subject": "fix: [security] Imported decaying models belong to the"
}
],
"source": "https://github.com/MISP/MISP/commit/70e319e4b.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:55:12Z",
"version": "2.0.3"
},
"subject": "fix: [security] Imported decaying models belong to the",
"tagVersionBoundary": {
"commits_after_fix": 21,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-915",
"rationale": "The import endpoint accepted user-supplied data and saved it without restricting which object attributes could be set. A nested model key allowed the attacker to modify the primary key, organisation, and default flag of a record, which are attributes that should be controlled exclusively by the application. This is a classic mass-assignment / improper dynamic attribute modification issue."
},
{
"cweId": "CWE-285",
"rationale": "The application failed to enforce that the imported model belongs to the caller\u0027s organisation. A user with only perm_decaying could modify records owned by other organisations, indicating an authorization boundary was not enforced on the object being written."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (70e319e4b9dbbeca173befce2340eedf9d86f1b0): fix: [security] Imported decaying models belong to the",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/70e319e4b.patch"
],
"timestamp": "2026-09-25T12:22:03Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20189"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104908",
"datePublished": "2026-10-02T15:56:13.969Z",
"dateReserved": "2026-10-02T15:56:12.330Z",
"dateUpdated": "2026-10-02T16:19:17.687Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104907 (GCVE-0-2026-104907)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:51 – Updated: 2026-10-02 16:18| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/70ad174dd | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 15:50 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/70ad174dd.patch
048909e6f2d9… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
70ad174ddd43
|
fix: [security] Cast the remote tag id in the event preview | 048909e6f2d9… |
Fix summary
The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.
Patch summary
In app/View/Servers/preview_event.ctp, the expression h($tag['id']) inside the onclick attribute's JavaScript string was replaced with (int)$tag['id']. This changes the output from an HTML-escaped string to a strictly integer value, preventing any non-numeric characters from being injected into the inline script context.
CVSS rationale
AV:N - the attack originates from a remote linked server over the network. AC:L - the injection is straightforward (embed a quote in a tag ID). AT:N - no special timing or race conditions required. PR:L - the attacker must be a configured linked server, which requires some level of trust/access but not full admin. UI:A - the victim must actively view the event preview and interact with the tag element. VC/VI/VA:N - the MISP server itself is not compromised; the impact is in the victim's browser. SC:N - no meaningful confidentiality impact on the subsequent component is guaranteed. SI:L - the injected script can perform limited actions (redirect, read page data, submit forms) in the user's session. SA:N - no availability impact on the subsequent component.
Weakness rationale
- CWE-79 The tag ID is embedded in an inline JavaScript onclick handler where HTML escaping (h()) does not neutralize JavaScript string breakout characters. This is a classic case of improper output encoding for a JavaScript context, resulting in reflected XSS.
- CWE-116 The root cause is using HTML entity encoding (h()) in a context that requires JavaScript string escaping. The encoding mechanism is inappropriate for the output context, which is a sub-category of the XSS issue.
Attack pattern rationale
- CAPEC-1 The vulnerability is a reflected XSS where attacker-controlled data (a tag ID from a linked server) is injected into an inline JavaScript event handler without proper context-aware encoding. CAPEC-1 is the closest general match. The specific sub-technique is injection into a JavaScript string literal within an HTML attribute, which is not separately enumerated in CAPEC.
- CAPEC-126 The attacker exploits the fact that the single-quote character (or similar) is not properly handled when the tag ID is placed inside a JavaScript string within an HTML attribute. The HTML escaping does not account for the JavaScript string delimiter. This CAPEC captures the character-handling aspect of the flaw. Uncertainty: CAPEC-1 is more directly about XSS; CAPEC-126 is included as a supplementary mapping for the encoding mismatch.
Assumptions to verify
- The affected version boundary is inferred from the tag v2.5.48 with 28 commits after the fix; the exact first affected version is not stated in the patch.
- The attacker is assumed to be a linked/remote MISP server that can control tag IDs in events shared with the local instance; the exact trust model and authentication for linked servers is not detailed in the patch.
- CAPEC-126 is included as a supplementary mapping; the primary and most defensible mapping is CAPEC-1 (Cross Site Scripting).
- The CVSS PR:L assumes that being a linked server requires some form of authenticated or trusted relationship, but the exact privilege level is not specified in the patch.
- The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is listed as a tool credit, not a human remediation developer.
- The impact scope (SC/SI) is assessed conservatively; the actual XSS payload capability depends on the browser context and same-origin policy, which are not fully specified.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 11 | medium | 6 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (70ad174ddd438887687d40fc1e2e4e8b322a179e): fix: [security] Cast the remote tag id in the event preview",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/70ad174dd.patch"
],
"timestamp": "2026-09-24T21:53:31Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104907",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:17:59.477633Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:18:12.403Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Servers/preview_event"
],
"product": "MISP",
"programFiles": [
"app/View/Servers/preview_event.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- A linked/remote MISP server is configured and connected to the local instance.\u003c/p\u003e\u003cp\u003e- The linked server supplies a crafted tag ID in an event.\u003c/p\u003e\u003cp\u003e- An authenticated user views the event preview and interacts with the affected tag element.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Arbitrary JavaScript execution in the context of the viewing user\u0027s browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.\u003c/p\u003e\u003cp\u003eAffected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed).\u003c/p\u003e"
}
],
"value": "MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context, meaning a malicious linked server could supply a tag ID containing characters (such as a single quote) that break out of the JavaScript string literal and inject arbitrary script.\n\nPreconditions:\n\n- A linked/remote MISP server is configured and connected to the local instance.\n\n- The linked server supplies a crafted tag ID in an event.\n\n- An authenticated user views the event preview and interacts with the affected tag element.\n\nImpact:\n\n- Arbitrary JavaScript execution in the context of the viewing user\u0027s browser session, potentially allowing session hijacking, data exfiltration, or unauthorized actions on behalf of the user.\n\nAffected versions: MISP prior to the fix commit (v2.5.48 or later, exact boundary unconfirmed)."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting"
}
]
},
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Exploiting Incorrectly Handled Special/Control Characters"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "LOW",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:50:34Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Cross-site Scripting (XSS)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-116",
"description": "CWE-116 Improper Encoding or Escaping of Output",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:51:34.565Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/70ad174dd"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters."
}
],
"title": "MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag v2.5.48 with 28 commits after the fix; the exact first affected version is not stated in the patch.",
"The attacker is assumed to be a linked/remote MISP server that can control tag IDs in events shared with the local instance; the exact trust model and authentication for linked servers is not detailed in the patch.",
"CAPEC-126 is included as a supplementary mapping; the primary and most defensible mapping is CAPEC-1 (Cross Site Scripting).",
"The CVSS PR:L assumes that being a linked server requires some form of authenticated or trusted relationship, but the exact privilege level is not specified in the patch.",
"The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is listed as a tool credit, not a human remediation developer.",
"The impact scope (SC/SI) is assessed conservatively; the actual XSS payload capability depends on the browser context and same-origin policy, which are not fully specified."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The vulnerability is a reflected XSS where attacker-controlled data (a tag ID from a linked server) is injected into an inline JavaScript event handler without proper context-aware encoding. CAPEC-1 is the closest general match. The specific sub-technique is injection into a JavaScript string literal within an HTML attribute, which is not separately enumerated in CAPEC."
},
{
"capecId": "CAPEC-126",
"rationale": "The attacker exploits the fact that the single-quote character (or similar) is not properly handled when the tag ID is placed inside a JavaScript string within an HTML attribute. The HTML escaping does not account for the JavaScript string delimiter. This CAPEC captures the character-handling aspect of the flaw. Uncertainty: CAPEC-1 is more directly about XSS; CAPEC-126 is included as a supplementary mapping for the encoding mismatch."
}
],
"commit": "70ad174ddd438887687d40fc1e2e4e8b322a179e",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N - the attack originates from a remote linked server over the network. AC:L - the injection is straightforward (embed a quote in a tag ID). AT:N - no special timing or race conditions required. PR:L - the attacker must be a configured linked server, which requires some level of trust/access but not full admin. UI:A - the victim must actively view the event preview and interact with the tag element. VC/VI/VA:N - the MISP server itself is not compromised; the impact is in the victim\u0027s browser. SC:N - no meaningful confidentiality impact on the subsequent component is guaranteed. SI:L - the injected script can perform limited actions (redirect, read page data, submit forms) in the user\u0027s session. SA:N - no availability impact on the subsequent component.",
"fixSummary": "The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters.",
"generatedAt": "2026-10-02T15:50:34.593118Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "048909e6f2d91cc9e6f920e8416edc5f9f44410eba1becc15373378f46a221de",
"patchSummary": "In app/View/Servers/preview_event.ctp, the expression h($tag[\u0027id\u0027]) inside the onclick attribute\u0027s JavaScript string was replaced with (int)$tag[\u0027id\u0027]. This changes the output from an HTML-escaped string to a strictly integer value, preventing any non-numeric characters from being injected into the inline script context.",
"patchTruncated": false,
"patches": [
{
"commit": "70ad174ddd438887687d40fc1e2e4e8b322a179e",
"date": "Thu, 24 Sep 2026 23:53:31 +0200",
"patchSha256": "048909e6f2d91cc9e6f920e8416edc5f9f44410eba1becc15373378f46a221de",
"source": "https://github.com/MISP/MISP/commit/70ad174dd.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/70ad174dd.patch",
"subject": "fix: [security] Cast the remote tag id in the event preview"
}
],
"source": "https://github.com/MISP/MISP/commit/70ad174dd.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:50:34Z",
"version": "2.0.3"
},
"subject": "fix: [security] Cast the remote tag id in the event preview",
"tagVersionBoundary": {
"commits_after_fix": 28,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The tag ID is embedded in an inline JavaScript onclick handler where HTML escaping (h()) does not neutralize JavaScript string breakout characters. This is a classic case of improper output encoding for a JavaScript context, resulting in reflected XSS."
},
{
"cweId": "CWE-116",
"rationale": "The root cause is using HTML entity encoding (h()) in a context that requires JavaScript string escaping. The encoding mechanism is inappropriate for the output context, which is a sub-category of the XSS issue."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (70ad174ddd438887687d40fc1e2e4e8b322a179e): fix: [security] Cast the remote tag id in the event preview",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/70ad174dd.patch"
],
"timestamp": "2026-09-24T21:53:31Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20154"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104907",
"datePublished": "2026-10-02T15:51:34.565Z",
"dateReserved": "2026-10-02T15:51:32.541Z",
"dateUpdated": "2026-10-02T16:18:12.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104906 (GCVE-0-2026-104906)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:49 – Updated: 2026-10-02 16:17- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/1bed4ca0c | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 15:47 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/1bed4ca0c.patch
6f48e50f2a68… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
1bed4ca0c990
|
fix: [security] Escape the JSON shown in the generic JSON | 6f48e50f2a68… |
Fix summary
The fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector.
Patch summary
In app/View/Elements/genericElements/json.ctp, the sprintf call that builds the pre tag was changed from json_encode($json) to h(json_encode($json)). The h() function (CakePHP's HTML-encoding helper, equivalent to htmlspecialchars) now escapes angle brackets, ampersands, and quotes in the JSON output before it is placed inside the HTML pre element. One line changed, one file affected.
CVSS rationale
AV:N: The vulnerability is exploitable over the network via the MISP web interface. AC:L: No race conditions or special timing required; simply viewing the object triggers the XSS. AT:N: The malicious payload is already embedded in the TAXII object; no manipulation of the attack target is needed at exploit time. PR:L: The attacker needs a MISP account (or the ability to publish to a subscribed TAXII server) to place the payload. UI:A: The victim must actively open/view the TAXII object in the viewer. VC/VI/VA:N: The MISP server itself is not compromised; the impact is client-side. SC:H: An attacker can read session cookies, API tokens, and data visible in the MISP UI. SI:H: An attacker can perform actions as the authenticated user (create/modify objects, change settings). SA:N: No denial-of-service impact on the system.
Weakness rationale
- CWE-79 The patch directly addresses the failure to HTML-encode untrusted JSON data before embedding it in an HTML context. The h() wrapper is the canonical fix for CWE-79 in CakePHP applications. The data originates from external TAXII objects and is rendered without encoding, allowing script injection.
Attack pattern rationale
- CAPEC-66 The attack pattern involves injecting script-enabled content into a web page via untrusted data (TAXII object string properties) that is rendered without encoding. CAPEC-66 is the most specific CAPEC for XSS. The uncertainty is that the exact delivery mechanism (stored in a TAXII server vs. reflected) is not fully specified in the patch, but the core pattern of unencoded user-controlled data in an HTML context matches CAPEC-66 precisely.
Assumptions to verify
- The affected version boundary (< 2.5.48) is inferred from the tag_version_boundary metadata (v2.5.48, 29 commits after fix); the patch metadata does not explicitly state a fixed version.
- PR:L assumes the TAXII object viewer requires authenticated access to MISP; if the viewer is accessible without authentication, PR would be None.
- The CAPEC-66 mapping is the closest available pattern for XSS; the exact delivery vector (stored via TAXII server vs. reflected) is not fully specified in the patch, but the core unencoded-output pattern is unambiguous.
- The Co-Authored-By line references an AI assistant (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer.
- UI:A assumes the victim must actively navigate to and render the specific TAXII object; if the object is auto-loaded in a dashboard, UI could be None.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
8 | 11 | high | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (1bed4ca0c990a4c285e8caa1d7efd91fec43eaca): fix: [security] Escape the JSON shown in the generic JSON",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/1bed4ca0c.patch"
],
"timestamp": "2026-09-24T21:24:48Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104906",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:17:09.468515Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:17:21.730Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"TAXII object viewer",
"app/View/Elements/genericElements/json.ctp"
],
"product": "MISP",
"programFiles": [
"app/View/Elements/genericElements/json.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim\u0027s MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim\u0027s MISP session.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The victim must be an authenticated MISP user with access to the TAXII object viewer.\u003c/p\u003e\u003cp\u003e- The victim must open or view the crafted TAXII object.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\u003c/p\u003e\u003cp\u003e- Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface.\u003c/p\u003e\u003cp\u003e- Potential for performing actions on behalf of the authenticated user.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim\u0027s MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim\u0027s MISP session.\n\nPreconditions:\n\n- The victim must be an authenticated MISP user with access to the TAXII object viewer.\n\n- The victim must open or view the crafted TAXII object.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\n\n- Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface.\n\n- Potential for performing actions on behalf of the authenticated user.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-66",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-66 Cross Site Scripting (XSS)"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:47:29Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:49:32.948Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/1bed4ca0c"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector.\u003c/p\u003e"
}
],
"value": "The fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector."
}
],
"title": "MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary (\u003c 2.5.48) is inferred from the tag_version_boundary metadata (v2.5.48, 29 commits after fix); the patch metadata does not explicitly state a fixed version.",
"PR:L assumes the TAXII object viewer requires authenticated access to MISP; if the viewer is accessible without authentication, PR would be None.",
"The CAPEC-66 mapping is the closest available pattern for XSS; the exact delivery vector (stored via TAXII server vs. reflected) is not fully specified in the patch, but the core unencoded-output pattern is unambiguous.",
"The Co-Authored-By line references an AI assistant (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer.",
"UI:A assumes the victim must actively navigate to and render the specific TAXII object; if the object is auto-loaded in a dashboard, UI could be None."
],
"capecRationale": [
{
"capecId": "CAPEC-66",
"rationale": "The attack pattern involves injecting script-enabled content into a web page via untrusted data (TAXII object string properties) that is rendered without encoding. CAPEC-66 is the most specific CAPEC for XSS. The uncertainty is that the exact delivery mechanism (stored in a TAXII server vs. reflected) is not fully specified in the patch, but the core pattern of unencoded user-controlled data in an HTML context matches CAPEC-66 precisely."
}
],
"commit": "1bed4ca0c990a4c285e8caa1d7efd91fec43eaca",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N: The vulnerability is exploitable over the network via the MISP web interface. AC:L: No race conditions or special timing required; simply viewing the object triggers the XSS. AT:N: The malicious payload is already embedded in the TAXII object; no manipulation of the attack target is needed at exploit time. PR:L: The attacker needs a MISP account (or the ability to publish to a subscribed TAXII server) to place the payload. UI:A: The victim must actively open/view the TAXII object in the viewer. VC/VI/VA:N: The MISP server itself is not compromised; the impact is client-side. SC:H: An attacker can read session cookies, API tokens, and data visible in the MISP UI. SI:H: An attacker can perform actions as the authenticated user (create/modify objects, change settings). SA:N: No denial-of-service impact on the system.",
"fixSummary": "The fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector.",
"generatedAt": "2026-10-02T15:47:29.857932Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 8
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "6f48e50f2a682434a041678f85a824d0f37ffaf42dda6b0d664e756bc2c7d4b1",
"patchSummary": "In app/View/Elements/genericElements/json.ctp, the sprintf call that builds the pre tag was changed from json_encode($json) to h(json_encode($json)). The h() function (CakePHP\u0027s HTML-encoding helper, equivalent to htmlspecialchars) now escapes angle brackets, ampersands, and quotes in the JSON output before it is placed inside the HTML pre element. One line changed, one file affected.",
"patchTruncated": false,
"patches": [
{
"commit": "1bed4ca0c990a4c285e8caa1d7efd91fec43eaca",
"date": "Thu, 24 Sep 2026 23:24:48 +0200",
"patchSha256": "6f48e50f2a682434a041678f85a824d0f37ffaf42dda6b0d664e756bc2c7d4b1",
"source": "https://github.com/MISP/MISP/commit/1bed4ca0c.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/1bed4ca0c.patch",
"subject": "fix: [security] Escape the JSON shown in the generic JSON"
}
],
"source": "https://github.com/MISP/MISP/commit/1bed4ca0c.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:47:29Z",
"version": "2.0.3"
},
"subject": "fix: [security] Escape the JSON shown in the generic JSON",
"tagVersionBoundary": {
"commits_after_fix": 29,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The patch directly addresses the failure to HTML-encode untrusted JSON data before embedding it in an HTML context. The h() wrapper is the canonical fix for CWE-79 in CakePHP applications. The data originates from external TAXII objects and is rendered without encoding, allowing script injection."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (1bed4ca0c990a4c285e8caa1d7efd91fec43eaca): fix: [security] Escape the JSON shown in the generic JSON",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/1bed4ca0c.patch"
],
"timestamp": "2026-09-24T21:24:48Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20251"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104906",
"datePublished": "2026-10-02T15:49:32.948Z",
"dateReserved": "2026-10-02T15:49:31.457Z",
"dateUpdated": "2026-10-02T16:17:21.730Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104901 (GCVE-0-2026-104901)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:21 – Updated: 2026-10-02 16:15- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/bd5e80c84 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-02 15:17 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/bd5e80c84.patch
398814c5f528… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
bd5e80c84f0a
|
fix: [security] Treat the remote event id in the ID | 398814c5f528… |
Fix summary
The vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser.
Patch summary
In ServersController.php, the remote_event['id'] value is cast to (int) in two locations where it is stored in the remote_events array and where it is extracted from the API response. In app/View/Servers/id_translator.ctp, the h() escaping function is applied to remote_id in the anchor text and to both server_id and remote_id in the preview URL. In app/View/Themed/Overmind/Servers/id_translator.ctp, h() is applied to remote_id in the badge display and to server_id and remote_id in the preview link. An 'exception' key is also initialized to null in the first array construction for consistency.
CVSS rationale
AV:N: The attack originates from a remote linked server over the network. AC:L: No race conditions or special timing are required; the linked server simply returns a crafted ID. AT:N: No active user interaction is needed to set up the attack (the malicious server is already linked). PR:N: The attacker is the linked server itself and does not need credentials on the victim's instance. UI:A: The victim must actively navigate to the ID Translator page for the payload to execute. VC:N/VI:N/VA:N: The vulnerable component (MISP server) is not directly compromised; the impact is client-side. SC:L: A successful XSS can read cookies, session tokens, or page data in the victim's browser. SI:L: The attacker can modify the rendered page content. SA:N: No impact on the security authority of the system.
Weakness rationale
- CWE-79 The remote event ID returned by a linked server was rendered in HTML output without output encoding, allowing injection of arbitrary markup or script. The fix applies HTML escaping (h()) and integer casting, which is the canonical remediation for CWE-79.
Attack pattern rationale
- CAPEC-1 The closest CAPEC pattern is reflected XSS: data originating from an external source (the linked server's API response) is reflected into the rendered HTML page without encoding. The mapping is slightly imprecise because the data source is a server-to-server API response rather than a direct user-supplied request parameter, but the mechanism (untrusted data reflected into HTML) matches CAPEC-1 most closely among available patterns. CAPEC-120 (Persistent XSS) was considered but the data is not stored in the victim's database; it is fetched live from the remote server and rendered, making the reflected pattern a better fit.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 30 commits after fix); the exact first affected version is not specified in the patch.
- The CAPEC-1 mapping is the closest available pattern; the data source is a server-to-server API response rather than a direct HTTP request parameter, making the 'reflected' classification slightly imprecise.
- The attacker is assumed to be a configured linked MISP server; no evidence suggests the vulnerability is exploitable without a pre-existing server link.
- The UI:A rating assumes the victim must explicitly navigate to the ID Translator page; it is unclear whether any automated workflow could trigger this view without direct user action.
- The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (bd5e80c84f0ab853d88d14e14df9bd92786eb8f4): fix: [security] Treat the remote event id in the ID",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/bd5e80c84.patch"
],
"timestamp": "2026-09-24T21:24:11Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104901",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:15:35.943839Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:15:49.327Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"ServersController (idTranslator)",
"View/Servers/id_translator.ctp",
"View/Themed/Overmind/Servers/id_translator.ctp"
],
"product": "MISP",
"programFiles": [
"app/Controller/ServersController.php",
"app/View/Servers/id_translator.ctp",
"app/View/Themed/Overmind/Servers/id_translator.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output encoding.\u003c/p\u003e\u003cp\u003eA malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The victim must be an authenticated user of the host MISP instance.\u003c/p\u003e\u003cp\u003e- A linked server must be configured on the host instance.\u003c/p\u003e\u003cp\u003e- The victim must navigate to the ID Translator page for a given event.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output encoding.\n\nA malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks.\n\nPreconditions:\n\n- The victim must be an authenticated user of the host MISP instance.\n\n- A linked server must be configured on the host instance.\n\n- The victim must navigate to the ID Translator page for a given event.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 XSS - Reflected"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:17:39Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:21:53.492Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/bd5e80c84"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser."
}
],
"title": "MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 30 commits after fix); the exact first affected version is not specified in the patch.",
"The CAPEC-1 mapping is the closest available pattern; the data source is a server-to-server API response rather than a direct HTTP request parameter, making the \u0027reflected\u0027 classification slightly imprecise.",
"The attacker is assumed to be a configured linked MISP server; no evidence suggests the vulnerability is exploitable without a pre-existing server link.",
"The UI:A rating assumes the victim must explicitly navigate to the ID Translator page; it is unclear whether any automated workflow could trigger this view without direct user action.",
"The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The closest CAPEC pattern is reflected XSS: data originating from an external source (the linked server\u0027s API response) is reflected into the rendered HTML page without encoding. The mapping is slightly imprecise because the data source is a server-to-server API response rather than a direct user-supplied request parameter, but the mechanism (untrusted data reflected into HTML) matches CAPEC-1 most closely among available patterns. CAPEC-120 (Persistent XSS) was considered but the data is not stored in the victim\u0027s database; it is fetched live from the remote server and rendered, making the reflected pattern a better fit."
}
],
"commit": "bd5e80c84f0ab853d88d14e14df9bd92786eb8f4",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N: The attack originates from a remote linked server over the network. AC:L: No race conditions or special timing are required; the linked server simply returns a crafted ID. AT:N: No active user interaction is needed to set up the attack (the malicious server is already linked). PR:N: The attacker is the linked server itself and does not need credentials on the victim\u0027s instance. UI:A: The victim must actively navigate to the ID Translator page for the payload to execute. VC:N/VI:N/VA:N: The vulnerable component (MISP server) is not directly compromised; the impact is client-side. SC:L: A successful XSS can read cookies, session tokens, or page data in the victim\u0027s browser. SI:L: The attacker can modify the rendered page content. SA:N: No impact on the security authority of the system.",
"fixSummary": "The vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser.",
"generatedAt": "2026-10-02T15:17:39.791225Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "398814c5f528eb504bfc173c7ed3258a171d9f3feeca03d8ba4fff252d3a8c1f",
"patchSummary": "In ServersController.php, the remote_event[\u0027id\u0027] value is cast to (int) in two locations where it is stored in the remote_events array and where it is extracted from the API response. In app/View/Servers/id_translator.ctp, the h() escaping function is applied to remote_id in the anchor text and to both server_id and remote_id in the preview URL. In app/View/Themed/Overmind/Servers/id_translator.ctp, h() is applied to remote_id in the badge display and to server_id and remote_id in the preview link. An \u0027exception\u0027 key is also initialized to null in the first array construction for consistency.",
"patchTruncated": false,
"patches": [
{
"commit": "bd5e80c84f0ab853d88d14e14df9bd92786eb8f4",
"date": "Thu, 24 Sep 2026 23:24:11 +0200",
"patchSha256": "398814c5f528eb504bfc173c7ed3258a171d9f3feeca03d8ba4fff252d3a8c1f",
"source": "https://github.com/MISP/MISP/commit/bd5e80c84.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/bd5e80c84.patch",
"subject": "fix: [security] Treat the remote event id in the ID"
}
],
"source": "https://github.com/MISP/MISP/commit/bd5e80c84.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-02T15:17:39Z",
"version": "2.0.3"
},
"subject": "fix: [security] Treat the remote event id in the ID",
"tagVersionBoundary": {
"commits_after_fix": 30,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The remote event ID returned by a linked server was rendered in HTML output without output encoding, allowing injection of arbitrary markup or script. The fix applies HTML escaping (h()) and integer casting, which is the canonical remediation for CWE-79."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (bd5e80c84f0ab853d88d14e14df9bd92786eb8f4): fix: [security] Treat the remote event id in the ID",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/bd5e80c84.patch"
],
"timestamp": "2026-09-24T21:24:11Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20296"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104901",
"datePublished": "2026-10-02T15:21:53.492Z",
"dateReserved": "2026-10-02T15:21:46.840Z",
"dateUpdated": "2026-10-02T16:15:49.327Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104900 (GCVE-0-2026-104900)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:16 – Updated: 2026-10-02 16:15- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/2a2981a27 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 11:32 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/2a2981a27.patch
3c8a41f55b53… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
2a2981a27bd0
|
fix: [security] Escape the value of the count index field | 3c8a41f55b53… |
Fix summary
The vulnerability is remediated by applying HTML entity encoding to the count field value before it is rendered in the view template. This ensures that any HTML or script markup contained in the value from a remote server is neutralized and displayed as inert text rather than being interpreted by the browser.
Patch summary
In the CakePHP view template file app/View/Elements/genericElements/IndexTable/Fields/count.ctp, the assignment of $fieldValue was changed from a raw Hash::extract() call to one wrapped in the h() helper function (CakePHP's HTML-encoding utility). This single-line change ensures the extracted value is HTML-entity-encoded before being used in the template output, preventing injection of markup through the event identifier from a linked server.
CVSS rationale
AV:N - exploitation occurs over the network via a linked MISP server. AC:L - the attacker only needs to craft an event ID with HTML/JS; no race conditions or complex timing. AT:N - the malicious data is stored in the linked server; no active attack is needed at exploitation time. PR:L - the attacker needs low-privilege access to a linked MISP server to create/modify an event. UI:N - the victim only needs to view the remote event preview index page; no special interaction. VC/VI/VA:N - no direct impact on the MISP server's own confidentiality, integrity, or availability. SC:L - XSS allows reading some data (cookies, DOM) in the victim's browser. SI:L - attacker can modify what the victim sees in the browser. SA:N - no impact on security authority of the victim's system.
Weakness rationale
- CWE-79 The patch adds HTML encoding (h() function) to a value that was previously rendered raw in an HTML context. The commit message explicitly states the value was printed raw, allowing markup injection. This is a textbook stored/reflected XSS due to missing output encoding.
Attack pattern rationale
- CAPEC-1 The attack pattern involves injecting script or markup into a web page through a data field (event ID from a linked server) that is rendered without encoding. CAPEC-1 is the closest standard mapping for XSS via untrusted data rendered in a browser context. The specific vector here is a linked MISP server supplying crafted data, which is a variant of the general XSS injection pattern. No more specific CAPEC precisely captures the 'trusted remote server as injection vector' nuance, so CAPEC-1 is the best available match.
Assumptions to verify
- The affected version boundary is inferred from the nearest tag v2.5.48 with 31 commits after the fix; the exact last affected version is not explicitly stated in the patch.
- PR:L assumes the attacker needs at least low-privilege access to a linked MISP server to create or modify an event; if no authentication is required on the linked server, PR could be None.
- The CAPEC-1 mapping is the closest standard pattern; no CAPEC specifically covers 'XSS via data from a trusted remote server' as a distinct pattern.
- The Co-Authored-By line references an AI assistant (Claude Opus 5.5); it is listed as a tool credit rather than a human remediation developer.
- The commit date (24 Sep 2026) is in the future relative to typical CVE timelines; this is taken at face value from the patch metadata.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (2a2981a27bd06bfd6fa37866db1911637d52538c): fix: [security] Escape the value of the count index field",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/2a2981a27.patch"
],
"timestamp": "2026-09-24T20:20:05Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104900",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T16:14:50.253586Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:15:09.284Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Remote Event Preview Index Table (count field)"
],
"product": "MISP",
"programFiles": [
"app/View/Elements/genericElements/IndexTable/Fields/count.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated link URL but rendered the field value without HTML encoding. An attacker with the ability to create or modify events on a linked (remote) MISP server could craft an event identifier containing HTML or JavaScript markup. When a user on the local MISP instance views the remote event preview index, the unescaped value is rendered directly in the browser, allowing arbitrary script execution in the victim\u0027s session.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- A linked/remote MISP server is configured and connected to the local instance.\u003c/p\u003e\u003cp\u003e- The attacker has sufficient access on the linked server to create or modify an event with a crafted identifier.\u003c/p\u003e\u003cp\u003e- A victim user on the local instance views the remote event preview index page.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary JavaScript in the context of the MISP web application.\u003c/p\u003e\u003cp\u003e- Potential session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated link URL but rendered the field value without HTML encoding. An attacker with the ability to create or modify events on a linked (remote) MISP server could craft an event identifier containing HTML or JavaScript markup. When a user on the local MISP instance views the remote event preview index, the unescaped value is rendered directly in the browser, allowing arbitrary script execution in the victim\u0027s session.\n\nPreconditions:\n\n- A linked/remote MISP server is configured and connected to the local instance.\n\n- The attacker has sufficient access on the linked server to create or modify an event with a crafted identifier.\n\n- A victim user on the local instance views the remote event preview index page.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the context of the MISP web application.\n\n- Potential session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T11:32:45Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:16:27.485Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/2a2981a27"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by applying HTML entity encoding to the count field value before it is rendered in the view template. This ensures that any HTML or script markup contained in the value from a remote server is neutralized and displayed as inert text rather than being interpreted by the browser.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by applying HTML entity encoding to the count field value before it is rendered in the view template. This ensures that any HTML or script markup contained in the value from a remote server is neutralized and displayed as inert text rather than being interpreted by the browser."
}
],
"title": "MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the nearest tag v2.5.48 with 31 commits after the fix; the exact last affected version is not explicitly stated in the patch.",
"PR:L assumes the attacker needs at least low-privilege access to a linked MISP server to create or modify an event; if no authentication is required on the linked server, PR could be None.",
"The CAPEC-1 mapping is the closest standard pattern; no CAPEC specifically covers \u0027XSS via data from a trusted remote server\u0027 as a distinct pattern.",
"The Co-Authored-By line references an AI assistant (Claude Opus 5.5); it is listed as a tool credit rather than a human remediation developer.",
"The commit date (24 Sep 2026) is in the future relative to typical CVE timelines; this is taken at face value from the patch metadata."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The attack pattern involves injecting script or markup into a web page through a data field (event ID from a linked server) that is rendered without encoding. CAPEC-1 is the closest standard mapping for XSS via untrusted data rendered in a browser context. The specific vector here is a linked MISP server supplying crafted data, which is a variant of the general XSS injection pattern. No more specific CAPEC precisely captures the \u0027trusted remote server as injection vector\u0027 nuance, so CAPEC-1 is the best available match."
}
],
"commit": "2a2981a27bd06bfd6fa37866db1911637d52538c",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N - exploitation occurs over the network via a linked MISP server. AC:L - the attacker only needs to craft an event ID with HTML/JS; no race conditions or complex timing. AT:N - the malicious data is stored in the linked server; no active attack is needed at exploitation time. PR:L - the attacker needs low-privilege access to a linked MISP server to create/modify an event. UI:N - the victim only needs to view the remote event preview index page; no special interaction. VC/VI/VA:N - no direct impact on the MISP server\u0027s own confidentiality, integrity, or availability. SC:L - XSS allows reading some data (cookies, DOM) in the victim\u0027s browser. SI:L - attacker can modify what the victim sees in the browser. SA:N - no impact on security authority of the victim\u0027s system.",
"fixSummary": "The vulnerability is remediated by applying HTML entity encoding to the count field value before it is rendered in the view template. This ensures that any HTML or script markup contained in the value from a remote server is neutralized and displayed as inert text rather than being interpreted by the browser.",
"generatedAt": "2026-10-01T11:32:45.636394Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "3c8a41f55b536b1beaab7797cf106c1ef8f72ec83417cf60660c60171f939a5e",
"patchSummary": "In the CakePHP view template file app/View/Elements/genericElements/IndexTable/Fields/count.ctp, the assignment of $fieldValue was changed from a raw Hash::extract() call to one wrapped in the h() helper function (CakePHP\u0027s HTML-encoding utility). This single-line change ensures the extracted value is HTML-entity-encoded before being used in the template output, preventing injection of markup through the event identifier from a linked server.",
"patchTruncated": false,
"patches": [
{
"commit": "2a2981a27bd06bfd6fa37866db1911637d52538c",
"date": "Thu, 24 Sep 2026 22:20:05 +0200",
"patchSha256": "3c8a41f55b536b1beaab7797cf106c1ef8f72ec83417cf60660c60171f939a5e",
"source": "https://github.com/MISP/MISP/commit/2a2981a27.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/2a2981a27.patch",
"subject": "fix: [security] Escape the value of the count index field"
}
],
"source": "https://github.com/MISP/MISP/commit/2a2981a27.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T11:32:45Z",
"version": "2.0.3"
},
"subject": "fix: [security] Escape the value of the count index field",
"tagVersionBoundary": {
"commits_after_fix": 31,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The patch adds HTML encoding (h() function) to a value that was previously rendered raw in an HTML context. The commit message explicitly states the value was printed raw, allowing markup injection. This is a textbook stored/reflected XSS due to missing output encoding."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (2a2981a27bd06bfd6fa37866db1911637d52538c): fix: [security] Escape the value of the count index field",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/2a2981a27.patch"
],
"timestamp": "2026-09-24T20:20:05Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20230"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-104900",
"datePublished": "2026-10-02T15:16:27.485Z",
"dateReserved": "2026-10-02T15:16:25.316Z",
"dateUpdated": "2026-10-02T16:15:09.284Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103858 (GCVE-0-2026-103858)
Vulnerability from cvelistv5 – Published: 2026-10-01 11:31 – Updated: 2026-10-01 15:00- CWE-285 - Improper Authorization
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/79fbd4c75 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 11:16 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/79fbd4c75.patch
04551eba9b01… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
79fbd4c7580a
|
fix: [security] Apply the thread ACL when posting to a | 04551eba9b01… |
Fix summary
The fix replaces the limited org-only distribution check with a call to the thread's full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post's thread_id was added to prevent referencing posts without a valid thread association.
Patch summary
In PostsController.php add() method: (1) For the 'thread' target case, replaced the inline distribution==0 and org_id comparison with a call to Thread->checkIfAuthorised() before reading the thread; removed the separate _isSiteAdmin() bypass. (2) For the 'post' target case, added a check that the post has a non-empty thread_id, replaced the same limited distribution/org check with Thread->checkIfAuthorised(), and reordered the thread read to occur after the authorization check. Net: 8 insertions, 12 deletions in one file.
CVSS rationale
AV:N: web application accessible over network. AC:L: attacker only needs a valid thread_id or post_id, no race conditions or special timing. AT:N: no special attack prerequisites beyond authentication. PR:L: requires an authenticated MISP user account. UI:N: no victim interaction needed; the attacker directly issues the request. VC:L: attacker can read thread titles and quoted post content they should not see. VI:L: attacker can inject posts into unauthorized threads. VA:N: no availability impact. SC/SI/SA:N: no impact on subsequent components. The impact is bounded to the MISP instance's data and does not compromise the server or other systems.
Weakness rationale
- CWE-285 The authorization check was present but incomplete: it only verified org-level distribution (distribution==0) and org_id match, failing to enforce sharing-group membership and event-level ACL. This is a classic case of insufficient authorization logic rather than a completely missing check, making CWE-285 more precise than CWE-862.
Attack pattern rationale
- CAPEC-10 The attacker manipulates the target_id parameter (thread_id or post_id) in the posts/add request to reference a thread or post they do not have full access to. The incomplete server-side authorization check then permits the operation. CAPEC-10 is the closest available pattern for exploiting a server's failure to properly validate the authorization context of a user-supplied resource identifier. Uncertainty: no CAPEC specifically named 'Insecure Direct Object Reference' or 'Broken Access Control via Incomplete ACL' exists in the CAPEC catalog, so Parameter Tampering is the best available match.
Assumptions to verify
- The exact affected version range is uncertain; the tag boundary v2.5.48 with 42 commits after the fix suggests the fix landed around or before v2.5.48, but the precise first-affected and first-fixed versions are not stated in the patch.
- The checkIfAuthorised() method is assumed to enforce the full thread ACL including sharing groups and event visibility, based on the commit message description; the method's implementation is not included in the patch.
- CAPEC-10 (Parameter Tampering) is the closest available CAPEC mapping; no CAPEC specifically covers 'incomplete authorization check on a direct object reference' was identified in the catalog.
- The CVSS assumes the attacker already possesses a valid MISP account (PR:L); unauthenticated access is not indicated by the patch.
- The AI co-author (Claude Opus 5.5) is credited as a tool rather than a person, per the Co-Authored-By line.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (79fbd4c7580adc0518581351c3d8c3d5b3ac7c97): fix: [security] Apply the thread ACL when posting to a",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/79fbd4c75.patch"
],
"timestamp": "2026-09-23T13:27:08Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103858",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:00:37.761849Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:00:57.587Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"PostsController (discussion/thread posting)"
],
"product": "MISP",
"programFiles": [
"app/Controller/PostsController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "unspecified",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy and C\u00e9lien Desteucq of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.\u003c/p\u003e\u003cp\u003eAs a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:\u003c/p\u003e\u003cp\u003e- Read the thread title and the content of the quoted post\u003c/p\u003e\u003cp\u003e- Submit a new post into the discussion thread\u003c/p\u003e\u003cp\u003eThis constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).\u003c/p\u003e\u003cp\u003eAffected: \u0026lt;2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.\n\nAs a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:\n\n- Read the thread title and the content of the quoted post\n\n- Submit a new post into the discussion thread\n\nThis constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).\n\nAffected: \u003c2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-10",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-10 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T11:16:47Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285 Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T11:31:32.840Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/79fbd4c75"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix replaces the limited org-only distribution check with a call to the thread\u0027s full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post\u0027s thread_id was added to prevent referencing posts without a valid thread association.\u003c/p\u003e"
}
],
"value": "The fix replaces the limited org-only distribution check with a call to the thread\u0027s full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post\u0027s thread_id was added to prevent referencing posts without a valid thread association."
}
],
"title": "MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The exact affected version range is uncertain; the tag boundary v2.5.48 with 42 commits after the fix suggests the fix landed around or before v2.5.48, but the precise first-affected and first-fixed versions are not stated in the patch.",
"The checkIfAuthorised() method is assumed to enforce the full thread ACL including sharing groups and event visibility, based on the commit message description; the method\u0027s implementation is not included in the patch.",
"CAPEC-10 (Parameter Tampering) is the closest available CAPEC mapping; no CAPEC specifically covers \u0027incomplete authorization check on a direct object reference\u0027 was identified in the catalog.",
"The CVSS assumes the attacker already possesses a valid MISP account (PR:L); unauthenticated access is not indicated by the patch.",
"The AI co-author (Claude Opus 5.5) is credited as a tool rather than a person, per the Co-Authored-By line."
],
"capecRationale": [
{
"capecId": "CAPEC-10",
"rationale": "The attacker manipulates the target_id parameter (thread_id or post_id) in the posts/add request to reference a thread or post they do not have full access to. The incomplete server-side authorization check then permits the operation. CAPEC-10 is the closest available pattern for exploiting a server\u0027s failure to properly validate the authorization context of a user-supplied resource identifier. Uncertainty: no CAPEC specifically named \u0027Insecure Direct Object Reference\u0027 or \u0027Broken Access Control via Incomplete ACL\u0027 exists in the CAPEC catalog, so Parameter Tampering is the best available match."
}
],
"commit": "79fbd4c7580adc0518581351c3d8c3d5b3ac7c97",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy and C\u00e9lien Desteucq of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N: web application accessible over network. AC:L: attacker only needs a valid thread_id or post_id, no race conditions or special timing. AT:N: no special attack prerequisites beyond authentication. PR:L: requires an authenticated MISP user account. UI:N: no victim interaction needed; the attacker directly issues the request. VC:L: attacker can read thread titles and quoted post content they should not see. VI:L: attacker can inject posts into unauthorized threads. VA:N: no availability impact. SC/SI/SA:N: no impact on subsequent components. The impact is bounded to the MISP instance\u0027s data and does not compromise the server or other systems.",
"fixSummary": "The fix replaces the limited org-only distribution check with a call to the thread\u0027s full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post\u0027s thread_id was added to prevent referencing posts without a valid thread association.",
"generatedAt": "2026-10-01T11:16:47.016611Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "04551eba9b017a1a2ccf05a79c21466f3fd7095a42750bd2704d57b2e3730938",
"patchSummary": "In PostsController.php add() method: (1) For the \u0027thread\u0027 target case, replaced the inline distribution==0 and org_id comparison with a call to Thread-\u003echeckIfAuthorised() before reading the thread; removed the separate _isSiteAdmin() bypass. (2) For the \u0027post\u0027 target case, added a check that the post has a non-empty thread_id, replaced the same limited distribution/org check with Thread-\u003echeckIfAuthorised(), and reordered the thread read to occur after the authorization check. Net: 8 insertions, 12 deletions in one file.",
"patchTruncated": false,
"patches": [
{
"commit": "79fbd4c7580adc0518581351c3d8c3d5b3ac7c97",
"date": "Wed, 23 Sep 2026 15:27:08 +0200",
"patchSha256": "04551eba9b017a1a2ccf05a79c21466f3fd7095a42750bd2704d57b2e3730938",
"source": "https://github.com/MISP/MISP/commit/79fbd4c75.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/79fbd4c75.patch",
"subject": "fix: [security] Apply the thread ACL when posting to a"
}
],
"source": "https://github.com/MISP/MISP/commit/79fbd4c75.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T11:16:47Z",
"version": "2.0.3"
},
"subject": "fix: [security] Apply the thread ACL when posting to a",
"tagVersionBoundary": {
"commits_after_fix": 42,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-285",
"rationale": "The authorization check was present but incomplete: it only verified org-level distribution (distribution==0) and org_id match, failing to enforce sharing-group membership and event-level ACL. This is a classic case of insufficient authorization logic rather than a completely missing check, making CWE-285 more precise than CWE-862."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (79fbd4c7580adc0518581351c3d8c3d5b3ac7c97): fix: [security] Apply the thread ACL when posting to a",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/79fbd4c75.patch"
],
"timestamp": "2026-09-23T13:27:08Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20244"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103858",
"datePublished": "2026-10-01T11:31:32.840Z",
"dateReserved": "2026-10-01T11:31:31.101Z",
"dateUpdated": "2026-10-01T15:00:57.587Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103664 (GCVE-0-2026-103664)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:55 – Updated: 2026-10-01 15:06- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/58925dbf0 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 08:49 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/58925dbf0.patch
7e384946a0fb… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
58925dbf01c2
|
fix: [security] Cast the analyst data seed to an integer | 7e384946a0fb… |
Fix summary
The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.
Patch summary
In AttributesController.php and ObjectsController.php, the seed value set for the view is now cast to an integer with a fallback to a random integer if the cast yields zero. In the two analyst data view templates (generic_simple.ctp and thread.ctp), the seed variable is similarly cast to an integer before use in inline script, replacing the previous logic that only checked for emptiness without type enforcement.
CVSS rationale
AV:N - exploitable over the network via a crafted URL. AC:L - no race conditions or special conditions; a simple URL with a malicious seed suffices. AT:N - no prior manipulation of the target system needed. PR:L - MISP is an authenticated platform; the attacker needs at least a low-privilege account or must target an authenticated user. UI:A - the victim must actively navigate to the crafted URL. VC/VI/VA:N - the server-side confidentiality, integrity, and availability are not directly impacted. SC:L - the victim's browser session data (cookies, tokens) can be read. SI:L - the victim's page content can be modified. SA:N - no impact on security authority.
Weakness rationale
- CWE-79 The user-supplied seed parameter was reflected into inline JavaScript in the HTML response without sanitization or type coercion, allowing script injection. This is a textbook reflected XSS.
Attack pattern rationale
- CAPEC-1 The attacker supplies a malicious value in a URL parameter (seed), which the server reflects unmodified into inline JavaScript in the HTTP response. The victim's browser executes the injected script. This matches the reflected XSS pattern precisely. No uncertainty in this mapping.
Assumptions to verify
- MISP requires user authentication to access the analyst data views; PR:L assumes a low-privilege authenticated account is sufficient for the attacker to craft or deliver the malicious URL.
- The exact fixed version number is not stated in the patch; the fix commit is 32 commits after the v2.5.48 tag, so the fixed version is presumed to be a release after 2.5.48.
- The UI:A rating assumes the victim must click a link or navigate to the crafted URL; if the seed could be injected via a different vector requiring no user interaction, UI could be None.
- CAPEC-1 (Reflected XSS) is selected as the closest match; the injection occurs server-side into the HTML response, distinguishing it from DOM-based XSS (CAPEC-64).
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
9 | 11 | high | 4 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (58925dbf01c2fe5dfe9b2f61a421f6463f66ca56): fix: [security] Cast the analyst data seed to an integer",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/58925dbf0.patch"
],
"timestamp": "2026-09-24T16:06:24Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103664",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:06:14.886463Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:06:25.374Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"AttributesController::viewAnalystData",
"ObjectsController::viewAnalystData",
"Analyst_data view templates"
],
"product": "MISP",
"programFiles": [
"app/Controller/AttributesController.php",
"app/Controller/ObjectsController.php",
"app/View/Elements/genericElements/Analyst_data/generic_simple.ctp",
"app/View/Elements/genericElements/Analyst_data/thread.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement.\u003c/p\u003e\u003cp\u003eAn attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim\u0027s browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The victim must be authenticated to MISP and access the analyst data view for an attribute or object.\u003c/p\u003e\u003cp\u003e- The attacker must supply a malicious seed value in the URL path.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary JavaScript in the victim\u0027s browser session.\u003c/p\u003e\u003cp\u003e- Potential theft of session credentials or sensitive data visible in the page.\u003c/p\u003e\u003cp\u003e- Manipulation of the analyst data interface.\u003c/p\u003e\u003cp\u003eAffected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).\u003c/p\u003e"
}
],
"value": "MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement.\n\nAn attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim\u0027s browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim.\n\nPreconditions:\n\n- The victim must be authenticated to MISP and access the analyst data view for an attribute or object.\n\n- The attacker must supply a malicious seed value in the URL path.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim\u0027s browser session.\n\n- Potential theft of session credentials or sensitive data visible in the page.\n\n- Manipulation of the analyst data interface.\n\nAffected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48)."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 XSS - Reflected"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:49:54Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:55:51.589Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/58925dbf0"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector."
}
],
"title": "MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"MISP requires user authentication to access the analyst data views; PR:L assumes a low-privilege authenticated account is sufficient for the attacker to craft or deliver the malicious URL.",
"The exact fixed version number is not stated in the patch; the fix commit is 32 commits after the v2.5.48 tag, so the fixed version is presumed to be a release after 2.5.48.",
"The UI:A rating assumes the victim must click a link or navigate to the crafted URL; if the seed could be injected via a different vector requiring no user interaction, UI could be None.",
"CAPEC-1 (Reflected XSS) is selected as the closest match; the injection occurs server-side into the HTML response, distinguishing it from DOM-based XSS (CAPEC-64)."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The attacker supplies a malicious value in a URL parameter (seed), which the server reflects unmodified into inline JavaScript in the HTTP response. The victim\u0027s browser executes the injected script. This matches the reflected XSS pattern precisely. No uncertainty in this mapping."
}
],
"commit": "58925dbf01c2fe5dfe9b2f61a421f6463f66ca56",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N - exploitable over the network via a crafted URL. AC:L - no race conditions or special conditions; a simple URL with a malicious seed suffices. AT:N - no prior manipulation of the target system needed. PR:L - MISP is an authenticated platform; the attacker needs at least a low-privilege account or must target an authenticated user. UI:A - the victim must actively navigate to the crafted URL. VC/VI/VA:N - the server-side confidentiality, integrity, and availability are not directly impacted. SC:L - the victim\u0027s browser session data (cookies, tokens) can be read. SI:L - the victim\u0027s page content can be modified. SA:N - no impact on security authority.",
"fixSummary": "The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.",
"generatedAt": "2026-10-01T08:49:54.035056Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 4,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 9
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "7e384946a0fb4f1d43dee43a5374cabf2e70c31add4a6d2e4fa845cdc5ee5b37",
"patchSummary": "In AttributesController.php and ObjectsController.php, the seed value set for the view is now cast to an integer with a fallback to a random integer if the cast yields zero. In the two analyst data view templates (generic_simple.ctp and thread.ctp), the seed variable is similarly cast to an integer before use in inline script, replacing the previous logic that only checked for emptiness without type enforcement.",
"patchTruncated": false,
"patches": [
{
"commit": "58925dbf01c2fe5dfe9b2f61a421f6463f66ca56",
"date": "Thu, 24 Sep 2026 18:06:24 +0200",
"patchSha256": "7e384946a0fb4f1d43dee43a5374cabf2e70c31add4a6d2e4fa845cdc5ee5b37",
"source": "https://github.com/MISP/MISP/commit/58925dbf0.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/58925dbf0.patch",
"subject": "fix: [security] Cast the analyst data seed to an integer"
}
],
"source": "https://github.com/MISP/MISP/commit/58925dbf0.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:49:54Z",
"version": "2.0.3"
},
"subject": "fix: [security] Cast the analyst data seed to an integer",
"tagVersionBoundary": {
"commits_after_fix": 32,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The user-supplied seed parameter was reflected into inline JavaScript in the HTML response without sanitization or type coercion, allowing script injection. This is a textbook reflected XSS."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (58925dbf01c2fe5dfe9b2f61a421f6463f66ca56): fix: [security] Cast the analyst data seed to an integer",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/58925dbf0.patch"
],
"timestamp": "2026-09-24T16:06:24Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20241"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103664",
"datePublished": "2026-10-01T08:55:51.589Z",
"dateReserved": "2026-10-01T08:55:49.992Z",
"dateUpdated": "2026-10-01T15:06:25.374Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103662 (GCVE-0-2026-103662)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:48 – Updated: 2026-10-01 15:07- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/9619083c8 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 08:34 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/9619083c8.patch
0255a5f82ee8… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
9619083c8cea
|
fix: [security] Escape the tag name on the taxonomy tag | 0255a5f82ee8… |
Fix summary
The vulnerability is remediated by HTML-encoding the user-supplied tag name value before it is interpolated into the confirmation form description text. This ensures that any HTML metacharacters in the input are rendered as inert text rather than executable markup, neutralizing the reflected XSS vector.
Patch summary
Two view template files (app/View/Taxonomies/add_tag.ctp and app/View/Taxonomies/disable_tag.ctp) are modified. In each file, the raw request data value $this->request->data['Taxonomy']['name'] is wrapped with CakePHP's h() HTML-encoding helper function before being passed to the translation string that renders the confirmation description. This is a one-line change per file, adding the h() wrapper around the previously unescaped variable.
CVSS rationale
AV:N - the vulnerability is exploitable over the network via a crafted URL. AC:L - no race conditions or special conditions; simply visiting a crafted URL triggers the XSS. AT:N - no attack target manipulation required. PR:N - the attacker does not need authentication; they craft a URL for the admin to visit. UI:A - the administrator must actively navigate to the malicious URL. VC:L - the XSS can read session cookies and page data in the admin's browser. VI:L - the XSS can perform actions on behalf of the admin within the MISP interface. VA:N - no availability impact. SC/SI/SA:N - the impact is confined to the victim's browser session; no secondary system impact is evidenced.
Weakness rationale
- CWE-79 The patch directly addresses a reflected XSS: user-controlled input from the request is echoed into HTML output without encoding. The fix applies HTML entity encoding (h() helper), which is the canonical remediation for CWE-79.
Attack pattern rationale
- CAPEC-63 The commit message explicitly states the tag name is 'echoed from the URL unescaped, a reflected XSS.' The attacker supplies a malicious value via a URL parameter, the application reflects it into the HTML response without encoding, and the script executes in the victim's browser. This is a textbook reflected XSS pattern matching CAPEC-63 exactly.
Assumptions to verify
- The tag v2.5.48 is assumed to be the first release containing the fix based on the tag_version_boundary metadata showing 44 commits after the fix commit; the exact release version that first shipped the fix is not explicitly stated.
- The vulnerability requires the legacy taxonomy tag confirmation views to be in use; if MISP has migrated to a different UI for taxonomy management, the attack surface may not be reachable.
- PR:N is assumed because the attacker does not need their own MISP account; they only need to deliver a crafted URL to an authenticated admin. If the form is only reachable via authenticated session and the parameter cannot be injected via URL for unauthenticated users, PR could be elevated.
- The Co-Authored-By line references an AI tool (Claude Opus 5.5); this is not credited as a human contributor per standard CVE credit practices.
- CAPEC-63 is selected as the closest match; the exact CAPEC taxonomy does not have a more specific entry for reflected XSS in server-rendered template engines.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
8 | 11 | high | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (9619083c8cea496fd3ddbad5bf9be57c91fd2118): fix: [security] Escape the tag name on the taxonomy tag",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/9619083c8.patch"
],
"timestamp": "2026-09-23T09:17:07Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103662",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:07:07.862444Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:07:17.448Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Taxonomies (add_tag",
"disable_tag views)"
],
"product": "MISP",
"programFiles": [
"app/View/Taxonomies/add_tag.ctp",
"app/View/Taxonomies/disable_tag.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "C\u00e9lien Desteucq of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).\u003c/p\u003e\u003cp\u003eThe affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator\u0027s browser session.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.\u003c/p\u003e\u003cp\u003e- The victim must be an authenticated site administrator.\u003c/p\u003e\u003cp\u003e- The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).\u003c/p\u003e\u003cp\u003eSecurity impact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary client-side script in the context of the administrator\u0027s browser.\u003c/p\u003e\u003cp\u003e- Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.\u003c/p\u003e\u003cp\u003e- Potential for performing privileged actions on behalf of the administrator within the MISP interface.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).\n\nThe affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator\u0027s browser session.\n\nPreconditions:\n\n- The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.\n\n- The victim must be an authenticated site administrator.\n\n- The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).\n\nSecurity impact:\n\n- Execution of arbitrary client-side script in the context of the administrator\u0027s browser.\n\n- Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.\n\n- Potential for performing privileged actions on behalf of the administrator within the MISP interface.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-63",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-63 Reflected Cross-Site Scripting"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:34:46Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:48:38.222Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/9619083c8"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by HTML-encoding the user-supplied tag name value before it is interpolated into the confirmation form description text. This ensures that any HTML metacharacters in the input are rendered as inert text rather than executable markup, neutralizing the reflected XSS vector.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by HTML-encoding the user-supplied tag name value before it is interpolated into the confirmation form description text. This ensures that any HTML metacharacters in the input are rendered as inert text rather than executable markup, neutralizing the reflected XSS vector."
}
],
"title": "MISP Reflected XSS in Taxonomy Tag Confirmation Forms",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The tag v2.5.48 is assumed to be the first release containing the fix based on the tag_version_boundary metadata showing 44 commits after the fix commit; the exact release version that first shipped the fix is not explicitly stated.",
"The vulnerability requires the legacy taxonomy tag confirmation views to be in use; if MISP has migrated to a different UI for taxonomy management, the attack surface may not be reachable.",
"PR:N is assumed because the attacker does not need their own MISP account; they only need to deliver a crafted URL to an authenticated admin. If the form is only reachable via authenticated session and the parameter cannot be injected via URL for unauthenticated users, PR could be elevated.",
"The Co-Authored-By line references an AI tool (Claude Opus 5.5); this is not credited as a human contributor per standard CVE credit practices.",
"CAPEC-63 is selected as the closest match; the exact CAPEC taxonomy does not have a more specific entry for reflected XSS in server-rendered template engines."
],
"capecRationale": [
{
"capecId": "CAPEC-63",
"rationale": "The commit message explicitly states the tag name is \u0027echoed from the URL unescaped, a reflected XSS.\u0027 The attacker supplies a malicious value via a URL parameter, the application reflects it into the HTML response without encoding, and the script executes in the victim\u0027s browser. This is a textbook reflected XSS pattern matching CAPEC-63 exactly."
}
],
"commit": "9619083c8cea496fd3ddbad5bf9be57c91fd2118",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "C\u00e9lien Desteucq of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N - the vulnerability is exploitable over the network via a crafted URL. AC:L - no race conditions or special conditions; simply visiting a crafted URL triggers the XSS. AT:N - no attack target manipulation required. PR:N - the attacker does not need authentication; they craft a URL for the admin to visit. UI:A - the administrator must actively navigate to the malicious URL. VC:L - the XSS can read session cookies and page data in the admin\u0027s browser. VI:L - the XSS can perform actions on behalf of the admin within the MISP interface. VA:N - no availability impact. SC/SI/SA:N - the impact is confined to the victim\u0027s browser session; no secondary system impact is evidenced.",
"fixSummary": "The vulnerability is remediated by HTML-encoding the user-supplied tag name value before it is interpolated into the confirmation form description text. This ensures that any HTML metacharacters in the input are rendered as inert text rather than executable markup, neutralizing the reflected XSS vector.",
"generatedAt": "2026-10-01T08:34:46.777011Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 8
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "0255a5f82ee8c34e3f27c236a85f0dfc4379393d7e75c42d4d33fbc6d6b151ac",
"patchSummary": "Two view template files (app/View/Taxonomies/add_tag.ctp and app/View/Taxonomies/disable_tag.ctp) are modified. In each file, the raw request data value $this-\u003erequest-\u003edata[\u0027Taxonomy\u0027][\u0027name\u0027] is wrapped with CakePHP\u0027s h() HTML-encoding helper function before being passed to the translation string that renders the confirmation description. This is a one-line change per file, adding the h() wrapper around the previously unescaped variable.",
"patchTruncated": false,
"patches": [
{
"commit": "9619083c8cea496fd3ddbad5bf9be57c91fd2118",
"date": "Wed, 23 Sep 2026 11:17:07 +0200",
"patchSha256": "0255a5f82ee8c34e3f27c236a85f0dfc4379393d7e75c42d4d33fbc6d6b151ac",
"source": "https://github.com/MISP/MISP/commit/9619083c8.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/9619083c8.patch",
"subject": "fix: [security] Escape the tag name on the taxonomy tag"
}
],
"source": "https://github.com/MISP/MISP/commit/9619083c8.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:34:46Z",
"version": "2.0.3"
},
"subject": "fix: [security] Escape the tag name on the taxonomy tag",
"tagVersionBoundary": {
"commits_after_fix": 44,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The patch directly addresses a reflected XSS: user-controlled input from the request is echoed into HTML output without encoding. The fix applies HTML entity encoding (h() helper), which is the canonical remediation for CWE-79."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (9619083c8cea496fd3ddbad5bf9be57c91fd2118): fix: [security] Escape the tag name on the taxonomy tag",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/9619083c8.patch"
],
"timestamp": "2026-09-23T09:17:07Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20300"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103662",
"datePublished": "2026-10-01T08:48:38.222Z",
"dateReserved": "2026-10-01T08:48:36.324Z",
"dateUpdated": "2026-10-01T15:07:17.448Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103659 (GCVE-0-2026-103659)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:33 – Updated: 2026-10-01 15:24qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 08:10 - Model
qwen3.8:27b- Input
-
patch set (2 sources)
e74b42214be0… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
ab08edf9256b
|
fix: [security] Apply the object ACL to flattened attributes | ebc10168f16d… |
07f3486d50f2
|
fix: [event] Gate flattened attributes on the object ACL | 18601512c29d… |
Fix summary
The fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner.
Patch summary
In app/Model/Event.php, two code paths were modified. In fetchPaginatedAttributes(), a new subquery is generated against the Object table using the distribution and sharing-group ACL conditions, and an OR condition is added to the attribute query: either Attribute.object_id = 0 (top-level attribute) or the attribute's object passes the ACL. In fetchEvent(), when flatten is true and the user is not a site admin, a similar subquery is injected into the Attribute contain conditions. The second commit refactors the ACL condition into a standalone variable ($objectAclCondition) and uses only that condition (plus Object.id = Attribute.object_id) in the subquery, removing the soft-delete and other contain conditions that were incorrectly included. A regression test class (FlattenedObjectAcl) in tests/testregressions.py verifies: (1) an outsider cannot see organisation-only object attributes via flatten, (2) the owner retains soft-deleted attributes of a live object, and (3) the outsider cannot see another org's soft
CVSS rationale
AV:N - exploited over the network via the MISP REST API. AC:L - the attack is a simple API request with the flatten parameter; no race conditions or complex setup required. AT:N - no special target-side conditions beyond the existence of a community event with restricted objects. PR:L - requires an authenticated user with at least read access to the community event. UI:N - no user interaction needed; the API call is self-contained. VC:H - sensitive threat-intelligence attributes from organisation-only objects are fully exposed to unauthorized users. VI:N, VA:N - no integrity or availability impact on the vulnerable component. SC:N, SI:N, SA:N - no impact on subsequent components; the data resides within the same application.
Weakness rationale
- CWE-862 The flattening code path removed the Object contain (which enforced distribution and sharing-group ACLs) without re-applying an equivalent authorization check on the resulting top-level attributes. The object-level access control was simply absent from the flattened query, allowing unauthorized data access.
- CWE-285 The authorization decision for object attributes was based solely on the event-level distribution rather than the object-level distribution and sharing group. This is an improper authorization check that grants broader access than intended.
Attack pattern rationale
- CAPEC-126 The attacker (a legitimate user with access to a community event) exploits the fact that the application's privilege/access-control enforcement is incorrectly adjusted during the flatten operation. The object-level ACL is not applied, effectively elevating the user's data access beyond their intended scope. This is the closest CAPEC pattern to an authorization bypass where the application fails to enforce a narrower access control in a specific code path. Uncertainty: no CAPEC pattern specifically describes 'missing per-object ACL in a flattened view'; CAPEC-126 is the best available match for privilege/access-control bypass.
Assumptions to verify
- The affected version range is unspecified; the patch does not include version tags or release boundaries. All MISP versions prior to the fix commit are assumed affected.
- The CVSS PR:L assumes the attacker needs at minimum a read-access role on the community event; no evidence supports a lower or higher privilege requirement.
- The CAPEC-126 mapping is the closest available pattern; no CAPEC specifically describes a missing per-object ACL in a flattened API response. The mapping is approximate.
- The second commit (soft-delete fix) is treated as part of the same vulnerability remediation per the patch-set assumption, though it addresses a regression introduced by the first fix rather than the original authorization bypass.
- AI co-authors (Claude Opus 4.8, Claude Opus 5) are listed in commit metadata but are not included as advisory credits as they are tooling, not human contributors.
- No evidence of active exploitation, public PoC, or in-the-wild abuse was found in the supplied data.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 11 | medium | 6 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (ab08edf9256bb3c9c8a382e0778ecd10b9e29c7c): fix: [security] Apply the object ACL to flattened attributes",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/ab08edf92.patch"
],
"timestamp": "2026-09-23T07:25:31Z",
"type": "fix-developed"
},
{
"description": "Corrective change authored (07f3486d50f2a5ee0f31ea66c920692664397ddb): fix: [event] Gate flattened attributes on the object ACL",
"id": "evt-fix-developed-2",
"references": [
"https://github.com/MISP/MISP/commit/07f3486d5.patch"
],
"timestamp": "2026-09-28T11:41:23Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103659",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:24:35.363182Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:24:42.585Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Event model (app/Model/Event.php)"
],
"product": "MISP",
"programFiles": [
"app/Model/Event.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Wenhao Wu"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes.\u003c/p\u003e\u003cp\u003eAs a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user\u0027s organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data.\u003c/p\u003e\u003cp\u003eA secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated user with access to a community-distributed event\u003c/p\u003e\u003cp\u003e- The event contains at least one object with a distribution level or sharing group that restricts access beyond the event\u0027s own distribution\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Unauthorized disclosure of attributes belonging to restricted objects\u003c/p\u003e\u003cp\u003e- Potential exposure of organisation-specific threat intelligence to other organisations\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes.\n\nAs a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user\u0027s organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data.\n\nA secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate.\n\nPreconditions:\n\n- An authenticated user with access to a community-distributed event\n\n- The event contains at least one object with a distribution level or sharing group that restricts access beyond the event\u0027s own distribution\n\nImpact:\n\n- Unauthorized disclosure of attributes belonging to restricted objects\n\n- Potential exposure of organisation-specific threat intelligence to other organisations\n\nAffected versions: \u003c2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Exploiting Incorrectly Adjusted Privileges"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:10:59Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285 Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:33:05.141Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/ab08edf92"
},
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/07f3486d5"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner.\u003c/p\u003e"
}
],
"value": "The fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner."
}
],
"title": "MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is unspecified; the patch does not include version tags or release boundaries. All MISP versions prior to the fix commit are assumed affected.",
"The CVSS PR:L assumes the attacker needs at minimum a read-access role on the community event; no evidence supports a lower or higher privilege requirement.",
"The CAPEC-126 mapping is the closest available pattern; no CAPEC specifically describes a missing per-object ACL in a flattened API response. The mapping is approximate.",
"The second commit (soft-delete fix) is treated as part of the same vulnerability remediation per the patch-set assumption, though it addresses a regression introduced by the first fix rather than the original authorization bypass.",
"AI co-authors (Claude Opus 4.8, Claude Opus 5) are listed in commit metadata but are not included as advisory credits as they are tooling, not human contributors.",
"No evidence of active exploitation, public PoC, or in-the-wild abuse was found in the supplied data."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The attacker (a legitimate user with access to a community event) exploits the fact that the application\u0027s privilege/access-control enforcement is incorrectly adjusted during the flatten operation. The object-level ACL is not applied, effectively elevating the user\u0027s data access beyond their intended scope. This is the closest CAPEC pattern to an authorization bypass where the application fails to enforce a narrower access control in a specific code path. Uncertainty: no CAPEC pattern specifically describes \u0027missing per-object ACL in a flattened view\u0027; CAPEC-126 is the best available match for privilege/access-control bypass."
}
],
"commit": "07f3486d50f2a5ee0f31ea66c920692664397ddb",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Wenhao Wu"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"cvssRationale": "AV:N - exploited over the network via the MISP REST API. AC:L - the attack is a simple API request with the flatten parameter; no race conditions or complex setup required. AT:N - no special target-side conditions beyond the existence of a community event with restricted objects. PR:L - requires an authenticated user with at least read access to the community event. UI:N - no user interaction needed; the API call is self-contained. VC:H - sensitive threat-intelligence attributes from organisation-only objects are fully exposed to unauthorized users. VI:N, VA:N - no integrity or availability impact on the vulnerable component. SC:N, SI:N, SA:N - no impact on subsequent components; the data resides within the same application.",
"fixSummary": "The fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner.",
"generatedAt": "2026-10-01T08:10:59.855811Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "e74b42214be094a3c715d859dd20b9ecd7091d30a187ab4583a7ec0f070c0581",
"patchSummary": "In app/Model/Event.php, two code paths were modified. In fetchPaginatedAttributes(), a new subquery is generated against the Object table using the distribution and sharing-group ACL conditions, and an OR condition is added to the attribute query: either Attribute.object_id = 0 (top-level attribute) or the attribute\u0027s object passes the ACL. In fetchEvent(), when flatten is true and the user is not a site admin, a similar subquery is injected into the Attribute contain conditions. The second commit refactors the ACL condition into a standalone variable ($objectAclCondition) and uses only that condition (plus Object.id = Attribute.object_id) in the subquery, removing the soft-delete and other contain conditions that were incorrectly included. A regression test class (FlattenedObjectAcl) in tests/testregressions.py verifies: (1) an outsider cannot see organisation-only object attributes via flatten, (2) the owner retains soft-deleted attributes of a live object, and (3) the outsider cannot see another org\u0027s soft",
"patchTruncated": false,
"patches": [
{
"commit": "ab08edf9256bb3c9c8a382e0778ecd10b9e29c7c",
"date": "Wed, 23 Sep 2026 09:25:31 +0200",
"patchSha256": "ebc10168f16d00a458d924a62fe76e00277217c8449c694eeb4442d6d3a724a0",
"source": "https://github.com/MISP/MISP/commit/ab08edf92.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/ab08edf92.patch",
"subject": "fix: [security] Apply the object ACL to flattened attributes"
},
{
"commit": "07f3486d50f2a5ee0f31ea66c920692664397ddb",
"date": "Mon, 28 Sep 2026 13:41:23 +0200",
"patchSha256": "18601512c29df510bfdc629de713cffd41af868e7d230374aa346c92829e40de",
"source": "https://github.com/MISP/MISP/commit/07f3486d5.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/07f3486d5.patch",
"subject": "fix: [event] Gate flattened attributes on the object ACL"
}
],
"source": "patch set (2 sources)",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:10:59Z",
"version": "2.0.3"
},
"subject": "fix: [event] Gate flattened attributes on the object ACL",
"weaknessRationale": [
{
"cweId": "CWE-862",
"rationale": "The flattening code path removed the Object contain (which enforced distribution and sharing-group ACLs) without re-applying an equivalent authorization check on the resulting top-level attributes. The object-level access control was simply absent from the flattened query, allowing unauthorized data access."
},
{
"cweId": "CWE-285",
"rationale": "The authorization decision for object attributes was based solely on the event-level distribution rather than the object-level distribution and sharing group. This is an improper authorization check that grants broader access than intended."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (ab08edf9256bb3c9c8a382e0778ecd10b9e29c7c): fix: [security] Apply the object ACL to flattened attributes",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/ab08edf92.patch"
],
"timestamp": "2026-09-23T07:25:31Z",
"type": "fix-developed"
},
{
"description": "Corrective change authored (07f3486d50f2a5ee0f31ea66c920692664397ddb): fix: [event] Gate flattened attributes on the object ACL",
"id": "evt-fix-developed-2",
"references": [
"https://github.com/MISP/MISP/commit/07f3486d5.patch"
],
"timestamp": "2026-09-28T11:41:23Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20257"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103659",
"datePublished": "2026-10-01T08:33:05.141Z",
"dateReserved": "2026-10-01T08:33:03.219Z",
"dateUpdated": "2026-10-01T15:24:42.585Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103655 (GCVE-0-2026-103655)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:08 – Updated: 2026-10-01 15:25- CWE-294 - Authentication Bypass via Logical Flaw
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/a020fa47b | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 07:52 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/a020fa47b.patch
6fce2d1f789e… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
a020fa47b6c3
|
fix: [security] Refuse a TOTP code that was already used to | 6fce2d1f789e… |
Fix summary
The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.
Patch summary
In app/Controller/UsersController.php, the otp() method was modified to capture the current timestamp and pass it to the TOTP verify call. A new private method __claimTotpStep() was added, which computes the TOTP step (intdiv of elapsed time over period), constructs a Redis key of the form misp:otp:totp_used:{userId}:{step}, and attempts a SET with NX and EX (3x period) flags via RedisTool. The login proceeds only if both the TOTP verification and the claim succeed. Thirteen lines added, one line modified.
CVSS rationale
AV:N: the TOTP code is transmitted over the network during login. AC:H: exploitation requires the attacker to intercept a valid TOTP code during a legitimate login and replay it within the short validity window (typically 30 s), which is a non-trivial timing and positioning requirement. AT:N: no manipulation of the target system is needed. PR:N: the attacker is unauthenticated. UI:N: no user interaction beyond the victim's normal login is required. VC:H / VI:H: successful exploitation grants full access to the targeted user's account, including threat-intelligence data and administrative capabilities. VA:L: the attacker could disrupt services by modifying or deleting data. SC/SI/SA:N: no impact on secondary systems is evidenced.
Weakness rationale
- CWE-294 The TOTP verification logic accepted the same code multiple times within its validity period because no state was tracked to mark a period as consumed. This is a logical flaw in the authentication mechanism that permits replay of a valid one-time credential, fitting CWE-294 more precisely than the broader CWE-287.
Attack pattern rationale
- CAPEC-122 The closest available CAPEC pattern is Session Hijacking, as the attacker gains unauthorized access to a user's authenticated session by replaying a captured credential (the TOTP code). The mapping is imperfect because the attack targets a one-time authentication token rather than a persistent session identifier, and the window is very short (one TOTP period). No CAPEC specifically covers one-time-code replay, so CAPEC-122 is the best available match.
Assumptions to verify
- The affected version range is inferred from the tag_version_boundary (v2.5.48, 40 commits after fix); the exact first affected version is not stated in the patch metadata and is recorded as unspecified.
- The TOTP validity period is assumed to be the standard 30 seconds based on the OTPHP library default; the patch does not hard-code a specific period value.
- The CAPEC-122 mapping is the closest available pattern; no CAPEC specifically addresses one-time-code replay, so the mapping carries uncertainty.
- CVSS AC is rated High because exploitation requires intercepting a valid TOTP code during a live login and replaying it within a short time window; if the attacker already possesses the code (e.g., via a compromised client), complexity would be lower.
- The Redis dependency for the fix is assumed to be available in the deployment; if Redis is unavailable, the fix's behavior is not specified in the patch.
- The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 11 | medium | 6 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (a020fa47b6c3cb5b43d841afe2ccf149889fad6b): fix: [security] Refuse a TOTP code that was already used to",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/a020fa47b.patch"
],
"timestamp": "2026-09-23T14:24:44Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103655",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:25:45.460434Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:25:55.269Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"app/Controller/UsersController.php (otp method)"
],
"product": "MISP",
"programFiles": [
"app/Controller/UsersController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window.\u003c/p\u003e\u003cp\u003eThe issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user\u0027s login could replay it to authenticate a second session as that user.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The target user has TOTP-based two-factor authentication enabled.\u003c/p\u003e\u003cp\u003e- The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client).\u003c/p\u003e\u003cp\u003e- The replay must occur within the TOTP validity period.\u003c/p\u003e\u003cp\u003eSecurity impact:\u003c/p\u003e\u003cp\u003e- Unauthorized account access by replaying a captured one-time code.\u003c/p\u003e\u003cp\u003e- Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;v2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window.\n\nThe issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user\u0027s login could replay it to authenticate a second session as that user.\n\nPreconditions:\n\n- The target user has TOTP-based two-factor authentication enabled.\n\n- The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client).\n\n- The replay must occur within the TOTP validity period.\n\nSecurity impact:\n\n- Unauthorized account access by replaying a captured one-time code.\n\n- Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user.\n\nAffected versions: \u003cv2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-122 Session Hijacking"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:52:43Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "CWE-294 Authentication Bypass via Logical Flaw",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:08:55.013Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/a020fa47b"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.\u003c/p\u003e"
}
],
"value": "The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window."
}
],
"title": "MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag_version_boundary (v2.5.48, 40 commits after fix); the exact first affected version is not stated in the patch metadata and is recorded as unspecified.",
"The TOTP validity period is assumed to be the standard 30 seconds based on the OTPHP library default; the patch does not hard-code a specific period value.",
"The CAPEC-122 mapping is the closest available pattern; no CAPEC specifically addresses one-time-code replay, so the mapping carries uncertainty.",
"CVSS AC is rated High because exploitation requires intercepting a valid TOTP code during a live login and replaying it within a short time window; if the attacker already possesses the code (e.g., via a compromised client), complexity would be lower.",
"The Redis dependency for the fix is assumed to be available in the deployment; if Redis is unavailable, the fix\u0027s behavior is not specified in the patch.",
"The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-122",
"rationale": "The closest available CAPEC pattern is Session Hijacking, as the attacker gains unauthorized access to a user\u0027s authenticated session by replaying a captured credential (the TOTP code). The mapping is imperfect because the attack targets a one-time authentication token rather than a persistent session identifier, and the window is very short (one TOTP period). No CAPEC specifically covers one-time-code replay, so CAPEC-122 is the best available match."
}
],
"commit": "a020fa47b6c3cb5b43d841afe2ccf149889fad6b",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N: the TOTP code is transmitted over the network during login. AC:H: exploitation requires the attacker to intercept a valid TOTP code during a legitimate login and replay it within the short validity window (typically 30 s), which is a non-trivial timing and positioning requirement. AT:N: no manipulation of the target system is needed. PR:N: the attacker is unauthenticated. UI:N: no user interaction beyond the victim\u0027s normal login is required. VC:H / VI:H: successful exploitation grants full access to the targeted user\u0027s account, including threat-intelligence data and administrative capabilities. VA:L: the attacker could disrupt services by modifying or deleting data. SC/SI/SA:N: no impact on secondary systems is evidenced.",
"fixSummary": "The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.",
"generatedAt": "2026-10-01T07:52:44.000034Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "6fce2d1f789e3b4c0cbb7b4d81079334f66f1707bb5422f49915393cab88143f",
"patchSummary": "In app/Controller/UsersController.php, the otp() method was modified to capture the current timestamp and pass it to the TOTP verify call. A new private method __claimTotpStep() was added, which computes the TOTP step (intdiv of elapsed time over period), constructs a Redis key of the form misp:otp:totp_used:{userId}:{step}, and attempts a SET with NX and EX (3x period) flags via RedisTool. The login proceeds only if both the TOTP verification and the claim succeed. Thirteen lines added, one line modified.",
"patchTruncated": false,
"patches": [
{
"commit": "a020fa47b6c3cb5b43d841afe2ccf149889fad6b",
"date": "Wed, 23 Sep 2026 16:24:44 +0200",
"patchSha256": "6fce2d1f789e3b4c0cbb7b4d81079334f66f1707bb5422f49915393cab88143f",
"source": "https://github.com/MISP/MISP/commit/a020fa47b.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/a020fa47b.patch",
"subject": "fix: [security] Refuse a TOTP code that was already used to"
}
],
"source": "https://github.com/MISP/MISP/commit/a020fa47b.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:52:44Z",
"version": "2.0.3"
},
"subject": "fix: [security] Refuse a TOTP code that was already used to",
"tagVersionBoundary": {
"commits_after_fix": 40,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-294",
"rationale": "The TOTP verification logic accepted the same code multiple times within its validity period because no state was tracked to mark a period as consumed. This is a logical flaw in the authentication mechanism that permits replay of a valid one-time credential, fitting CWE-294 more precisely than the broader CWE-287."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (a020fa47b6c3cb5b43d841afe2ccf149889fad6b): fix: [security] Refuse a TOTP code that was already used to",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/a020fa47b.patch"
],
"timestamp": "2026-09-23T14:24:44Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20194"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103655",
"datePublished": "2026-10-01T08:08:55.013Z",
"dateReserved": "2026-10-01T08:08:52.909Z",
"dateUpdated": "2026-10-01T15:25:55.269Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103651 (GCVE-0-2026-103651)
Vulnerability from cvelistv5 – Published: 2026-10-01 07:34 – Updated: 2026-10-01 15:32| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/f34aee2c7 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 07:22 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/f34aee2c7.patch
9ec05e4a3d95… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
f34aee2c74e1
|
fix: [security] Burn paper OTP tokens against the stored | 9ec05e4a3d95… |
Fix summary
The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused.
Patch summary
In UsersController::otp(), the inline HOTP verification block (which used the session-cached $user['hotp_counter']) is replaced with a call to a new private method __consumeHotp(). This method acquires a Redis SETNX lock (misp:otp:hotp_lock:{userId}, 10 s TTL), re-fetches the user's totp secret and hotp_counter from the database, verifies the submitted OTP against the stored counter, increments and saves the counter, and releases the lock in a finally block. The otp_user session key is now deleted after both TOTP and HOTP successful login paths. Net change: +36 / -5 lines in app/Controller/UsersController.php.
CVSS rationale
AV:N – MISP is a network-accessible web application. AC:H – exploitation requires a valid session with the password step already completed, possession of a valid HOTP token value, and the session must still hold the stale cached counter; multiple preconditions must align. AT:N – no manipulation of the target system is needed. PR:L – the attacker must be an authenticated user with a pending OTP session. UI:N – no additional user interaction is required beyond the initial login flow. VC:H – successful exploitation grants full access to the target user's MISP account and its data. VI:H – the attacker can perform any action the user is authorized to perform, and the counter corruption may affect subsequent legitimate authentication. VA:N – no denial-of-service impact is evident. SC/SI/SA:N – no secondary system impact is indicated by the patch.
Weakness rationale
- CWE-362 The HOTP counter is shared mutable state accessed without synchronization. The session-cached copy becomes stale relative to the database copy, and no lock is held during read-verify-increment, allowing a concurrent or replayed request to operate on the old value.
- CWE-287 The OTP verification logic accepts a token that has already been consumed because it compares against a stale cached counter rather than the authoritative stored counter, effectively weakening the second-factor authentication check.
Attack pattern rationale
- CAPEC-111 The vulnerability is exploited by exploiting the time window between the session-cached counter being set (at password entry) and the token being consumed, allowing a replayed token to be validated against the stale value. CAPEC-111 (Race Condition) is the closest available CAPEC pattern; the attack is not a classic TOCTOU on a file or memory location but rather a stale-cache race on a shared counter, which falls under the broader race-condition category. No more specific CAPEC for session-cached credential state replay exists in the CAPEC catalog, so this is the best available match.
Assumptions to verify
- The tag_version_boundary metadata (v2.5.48, 41 commits after fix) is interpreted as the first release containing the fix; no explicit fixed_version or affected_version was provided in the metadata.
- The CAPEC-111 mapping is the closest available pattern; the vulnerability is specifically a stale-session-cache replay rather than a classic TOCTOU race, and no more precise CAPEC exists in the catalog.
- CVSS PR:L assumes the attacker already has a valid authenticated session (password step completed); if the threat model requires unauthenticated access, PR would be None but AC would remain High.
- The Redis lock is assumed to be available in the deployment; if Redis is not configured, the locking mechanism may be bypassed, though this is a deployment concern not reflected in the patch.
- The Co-Authored-By line references an AI assistant; it is recorded as a tool credit rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (f34aee2c74e111fffd07e8ddde8e4843ccf998db): fix: [security] Burn paper OTP tokens against the stored",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/f34aee2c7.patch"
],
"timestamp": "2026-09-23T14:20:38Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103651",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:31:56.170497Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:32:08.372Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"app/Controller/UsersController.php"
],
"product": "MISP",
"programFiles": [
"app/Controller/UsersController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter.\u003c/p\u003e\u003cp\u003eThe HOTP verification logic compared the submitted token against a counter value that was cached in the user\u0027s session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The target user has HOTP (paper token) second-factor authentication enabled.\u003c/p\u003e\u003cp\u003e- The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending).\u003c/p\u003e\u003cp\u003e- The attacker has access to at least one HOTP token value (e.g., a paper token list).\u003c/p\u003e\u003cp\u003eSecurity impact:\u003c/p\u003e\u003cp\u003e- Bypass of the second authentication factor, allowing unauthorized access to a user\u0027s MISP account.\u003c/p\u003e\u003cp\u003e- Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter.\n\nThe HOTP verification logic compared the submitted token against a counter value that was cached in the user\u0027s session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state.\n\nPreconditions:\n\n- The target user has HOTP (paper token) second-factor authentication enabled.\n\n- The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending).\n\n- The attacker has access to at least one HOTP token value (e.g., a paper token list).\n\nSecurity impact:\n\n- Bypass of the second authentication factor, allowing unauthorized access to a user\u0027s MISP account.\n\n- Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-111",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-111 Race Condition"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:22:27Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-362",
"description": "CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T07:34:02.597Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/f34aee2c7"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused.\u003c/p\u003e"
}
],
"value": "The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused."
}
],
"title": "MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The tag_version_boundary metadata (v2.5.48, 41 commits after fix) is interpreted as the first release containing the fix; no explicit fixed_version or affected_version was provided in the metadata.",
"The CAPEC-111 mapping is the closest available pattern; the vulnerability is specifically a stale-session-cache replay rather than a classic TOCTOU race, and no more precise CAPEC exists in the catalog.",
"CVSS PR:L assumes the attacker already has a valid authenticated session (password step completed); if the threat model requires unauthenticated access, PR would be None but AC would remain High.",
"The Redis lock is assumed to be available in the deployment; if Redis is not configured, the locking mechanism may be bypassed, though this is a deployment concern not reflected in the patch.",
"The Co-Authored-By line references an AI assistant; it is recorded as a tool credit rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-111",
"rationale": "The vulnerability is exploited by exploiting the time window between the session-cached counter being set (at password entry) and the token being consumed, allowing a replayed token to be validated against the stale value. CAPEC-111 (Race Condition) is the closest available CAPEC pattern; the attack is not a classic TOCTOU on a file or memory location but rather a stale-cache race on a shared counter, which falls under the broader race-condition category. No more specific CAPEC for session-cached credential state replay exists in the CAPEC catalog, so this is the best available match."
}
],
"commit": "f34aee2c74e111fffd07e8ddde8e4843ccf998db",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N \u2013 MISP is a network-accessible web application. AC:H \u2013 exploitation requires a valid session with the password step already completed, possession of a valid HOTP token value, and the session must still hold the stale cached counter; multiple preconditions must align. AT:N \u2013 no manipulation of the target system is needed. PR:L \u2013 the attacker must be an authenticated user with a pending OTP session. UI:N \u2013 no additional user interaction is required beyond the initial login flow. VC:H \u2013 successful exploitation grants full access to the target user\u0027s MISP account and its data. VI:H \u2013 the attacker can perform any action the user is authorized to perform, and the counter corruption may affect subsequent legitimate authentication. VA:N \u2013 no denial-of-service impact is evident. SC/SI/SA:N \u2013 no secondary system impact is indicated by the patch.",
"fixSummary": "The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused.",
"generatedAt": "2026-10-01T07:22:27.568266Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "9ec05e4a3d95b183604c7e89e3fbb93950ac4d23dfe478809b868b6dfe85bad6",
"patchSummary": "In UsersController::otp(), the inline HOTP verification block (which used the session-cached $user[\u0027hotp_counter\u0027]) is replaced with a call to a new private method __consumeHotp(). This method acquires a Redis SETNX lock (misp:otp:hotp_lock:{userId}, 10 s TTL), re-fetches the user\u0027s totp secret and hotp_counter from the database, verifies the submitted OTP against the stored counter, increments and saves the counter, and releases the lock in a finally block. The otp_user session key is now deleted after both TOTP and HOTP successful login paths. Net change: +36 / -5 lines in app/Controller/UsersController.php.",
"patchTruncated": false,
"patches": [
{
"commit": "f34aee2c74e111fffd07e8ddde8e4843ccf998db",
"date": "Wed, 23 Sep 2026 16:20:38 +0200",
"patchSha256": "9ec05e4a3d95b183604c7e89e3fbb93950ac4d23dfe478809b868b6dfe85bad6",
"source": "https://github.com/MISP/MISP/commit/f34aee2c7.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/f34aee2c7.patch",
"subject": "fix: [security] Burn paper OTP tokens against the stored"
}
],
"source": "https://github.com/MISP/MISP/commit/f34aee2c7.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:22:27Z",
"version": "2.0.3"
},
"subject": "fix: [security] Burn paper OTP tokens against the stored",
"tagVersionBoundary": {
"commits_after_fix": 41,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-362",
"rationale": "The HOTP counter is shared mutable state accessed without synchronization. The session-cached copy becomes stale relative to the database copy, and no lock is held during read-verify-increment, allowing a concurrent or replayed request to operate on the old value."
},
{
"cweId": "CWE-287",
"rationale": "The OTP verification logic accepts a token that has already been consumed because it compares against a stale cached counter rather than the authoritative stored counter, effectively weakening the second-factor authentication check."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (f34aee2c74e111fffd07e8ddde8e4843ccf998db): fix: [security] Burn paper OTP tokens against the stored",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/f34aee2c7.patch"
],
"timestamp": "2026-09-23T14:20:38Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20307"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103651",
"datePublished": "2026-10-01T07:34:02.597Z",
"dateReserved": "2026-10-01T07:34:00.794Z",
"dateUpdated": "2026-10-01T15:32:08.372Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103389 (GCVE-0-2026-103389)
Vulnerability from cvelistv5 – Published: 2026-09-30 14:25 – Updated: 2026-09-30 15:28| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/8ea5783dd | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 14:24 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/8ea5783dd.patch
382869c811e8… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
8ea5783ddcfe
|
fix: [security] Galaxy icons are icon names, and the | 382869c811e8… |
Fix summary
The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.
Patch summary
Added a static isValidIconName() method and a regex constant (ICON_NAME_PATTERN) to the Galaxy model, plus a model-level validation rule restricting the icon field to lowercase letters, digits, and dashes. The captureGalaxy() method now blanks out any icon value that fails validation before persistence. CorrelationGraphTool::__createNode() now checks the icon against the validator and substitutes 'globe' for invalid stored values. Both correlation-graph.js and correlation-graphOvermind.js were changed from .html() string concatenation to .attr('class', ...) with a regex strip of non-conforming characters. AppController asset query version bumped from 225 to 226. A new PHPUnit test file (GalaxyIconNameTest.php) validates the icon name rule against known-good and known-bad payloads including the originally reported XSS vector.
CVSS rationale
AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special timing; simply set the icon field and wait for a victim to view the graph. AT:N: no manipulation of the attack target required. PR:L: requires an authenticated user with perm_galaxy_editor, which is the default stock User role. UI:A: the victim must actively open the correlation graph of an event containing the affected galaxy cluster. VC/VI/VA:N: the server-side application is not directly compromised; the impact is on the victim's browser session. SC:H: script execution in the victim's session can read cookies, tokens, and sensitive page data. SI:H: the attacker can modify the victim's view, inject content, or trigger actions. SA:N: no availability impact on the system.
Weakness rationale
- CWE-79 The galaxy icon field was stored without validation and later rendered into the DOM via D3 .html(), allowing an attacker to inject and execute arbitrary script in the victim's browser. This is a textbook stored XSS.
- CWE-20 The root enabler is the absence of any server-side validation on the icon field at write time (add, edit, capture). The field accepted arbitrary strings including HTML markup, which was the precondition for the XSS.
Attack pattern rationale
- CAPEC-1 The attack pattern is a stored XSS: an authenticated user with galaxy editor permission injects a script payload into a persistent data field (galaxy icon), which is later rendered unsanitized in another user's browser via the correlation graph. CAPEC-1 is the closest and most direct match. No more specific CAPEC entry for stored XSS via a data field rendered by a graphing library exists in the CAPEC catalog, so CAPEC-1 is the best available mapping.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata indicating the fix commit precedes v2.5.48 by 20 commits; no explicit 'fixed in' version is stated in the patch itself.
- The perm_galaxy_editor permission is assumed to be granted to the stock User role as stated in the commit message; the exact role-permission mapping was not independently verified from the patch.
- CAPEC-1 is the closest available mapping; no CAPEC entry specifically describes stored XSS via a graph-rendering library data field, so the general Cross Site Scripting pattern is used.
- CVSS UI:A assumes the victim must navigate to the correlation graph view of a specific event; if the graph is auto-loaded on a commonly visited page, UI could be lowered to Passive.
- The Co-Authored-By line references an AI assistant (Claude Fable 5.1); it is recorded as a tool credit rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103389",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:58:27.715153Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:06.728Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Galaxy model",
"Correlation Graph (default theme)",
"Correlation Graph (Overmind theme)",
"Galaxy sync/import capture"
],
"product": "MISP",
"programFiles": [
"app/Model/Galaxy.php",
"app/Lib/Tools/CorrelationGraphTool.php",
"app/webroot/js/correlation-graph.js",
"app/webroot/js/correlation-graphOvermind.js"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Fable 5.1"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.\u003c/p\u003e\u003cp\u003eA user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Arbitrary script execution in the context of the victim\u0027s MISP session\u003c/p\u003e\u003cp\u003e- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim\u003c/p\u003e\u003cp\u003e- Affects both the default and Overmind UI themes\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.\n\nA user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.\n\nImpact:\n\n- Arbitrary script execution in the context of the victim\u0027s MISP session\n\n- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim\n\n- Affects both the default and Overmind UI themes\n\nAffected versions: \u003c2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:25:59.230Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/8ea5783dd"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts."
}
],
"title": "MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata indicating the fix commit precedes v2.5.48 by 20 commits; no explicit \u0027fixed in\u0027 version is stated in the patch itself.",
"The perm_galaxy_editor permission is assumed to be granted to the stock User role as stated in the commit message; the exact role-permission mapping was not independently verified from the patch.",
"CAPEC-1 is the closest available mapping; no CAPEC entry specifically describes stored XSS via a graph-rendering library data field, so the general Cross Site Scripting pattern is used.",
"CVSS UI:A assumes the victim must navigate to the correlation graph view of a specific event; if the graph is auto-loaded on a commonly visited page, UI could be lowered to Passive.",
"The Co-Authored-By line references an AI assistant (Claude Fable 5.1); it is recorded as a tool credit rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The attack pattern is a stored XSS: an authenticated user with galaxy editor permission injects a script payload into a persistent data field (galaxy icon), which is later rendered unsanitized in another user\u0027s browser via the correlation graph. CAPEC-1 is the closest and most direct match. No more specific CAPEC entry for stored XSS via a data field rendered by a graphing library exists in the CAPEC catalog, so CAPEC-1 is the best available mapping."
}
],
"commit": "8ea5783ddcfe69be6013337a0d6732ac75a862e6",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Fable 5.1"
},
{
"lang": "en",
"type": "tool",
"value": "Claude Fable 5.1"
}
],
"cvssRationale": "AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special timing; simply set the icon field and wait for a victim to view the graph. AT:N: no manipulation of the attack target required. PR:L: requires an authenticated user with perm_galaxy_editor, which is the default stock User role. UI:A: the victim must actively open the correlation graph of an event containing the affected galaxy cluster. VC/VI/VA:N: the server-side application is not directly compromised; the impact is on the victim\u0027s browser session. SC:H: script execution in the victim\u0027s session can read cookies, tokens, and sensitive page data. SI:H: the attacker can modify the victim\u0027s view, inject content, or trigger actions. SA:N: no availability impact on the system.",
"fixSummary": "The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.",
"generatedAt": "2026-09-30T14:24:01.890608Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "382869c811e8df5875a463c4b6275f754f4969445196f08d708cfee926528b0f",
"patchSummary": "Added a static isValidIconName() method and a regex constant (ICON_NAME_PATTERN) to the Galaxy model, plus a model-level validation rule restricting the icon field to lowercase letters, digits, and dashes. The captureGalaxy() method now blanks out any icon value that fails validation before persistence. CorrelationGraphTool::__createNode() now checks the icon against the validator and substitutes \u0027globe\u0027 for invalid stored values. Both correlation-graph.js and correlation-graphOvermind.js were changed from .html() string concatenation to .attr(\u0027class\u0027, ...) with a regex strip of non-conforming characters. AppController asset query version bumped from 225 to 226. A new PHPUnit test file (GalaxyIconNameTest.php) validates the icon name rule against known-good and known-bad payloads including the originally reported XSS vector.",
"patchTruncated": false,
"patches": [
{
"commit": "8ea5783ddcfe69be6013337a0d6732ac75a862e6",
"patchSha256": "382869c811e8df5875a463c4b6275f754f4969445196f08d708cfee926528b0f",
"source": "https://github.com/MISP/MISP/commit/8ea5783dd.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/8ea5783dd.patch",
"subject": "fix: [security] Galaxy icons are icon names, and the"
}
],
"source": "https://github.com/MISP/MISP/commit/8ea5783dd.patch",
"subject": "fix: [security] Galaxy icons are icon names, and the",
"tagVersionBoundary": {
"commits_after_fix": 20,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The galaxy icon field was stored without validation and later rendered into the DOM via D3 .html(), allowing an attacker to inject and execute arbitrary script in the victim\u0027s browser. This is a textbook stored XSS."
},
{
"cweId": "CWE-20",
"rationale": "The root enabler is the absence of any server-side validation on the icon field at write time (add, edit, capture). The field accepted arbitrary strings including HTML markup, which was the precondition for the XSS."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20142"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103389",
"datePublished": "2026-09-30T14:25:59.230Z",
"dateReserved": "2026-09-30T14:25:56.802Z",
"dateUpdated": "2026-09-30T15:28:06.728Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103388 (GCVE-0-2026-103388)
Vulnerability from cvelistv5 – Published: 2026-09-30 14:22 – Updated: 2026-09-30 15:28- CWE-79 - Improper Neutralization of Input in Web Page ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/118528767 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 14:12 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/118528767.patch
b68dbd672692… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
118528767735
|
fix: [security] Link a galaxy cluster source only when it is | b68dbd672692… |
Fix summary
The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme.
Patch summary
Two view templates are modified. In app/View/GalaxyClusters/view.ctp, the source value is extracted into a local variable and the conditional for rendering an anchor tag now requires both FILTER_VALIDATE_URL and a preg_match against /^https?:\/\//i. In app/View/Themed/Overmind/Elements/GalaxyClusters/View/galaxy_clusters_general.ctp, the same preg_match guard is added to the existing FILTER_VALIDATE_URL check. Net effect: only http(s) URLs produce a clickable link; all other values (including javascript:) are rendered as plain escaped text.
CVSS rationale
AV:N – MISP is a web application accessed over the network. AC:L – no race conditions or special environment needed; storing a javascript: URL is straightforward. AT:N – no manipulation of the attack target required. PR:L – attacker needs galaxy editor privileges (authenticated, non-admin role). UI:A – victim must click the malicious link for script execution. VC/VI/VA:N – the MISP server itself is not directly compromised; impact is on the victim's browser. SC:H – attacker can read cookies, session tokens, and manipulate the DOM in the victim's session. SI:H – attacker can perform actions on behalf of the victim within MISP. SA:N – no direct compromise of the application's security controls or system integrity.
Weakness rationale
- CWE-79 The application renders user-controlled data (the galaxy cluster source field) into an HTML anchor tag without restricting the URI scheme to safe values. Although output is HTML-escaped via h(), the href attribute still accepts javascript: URIs, resulting in stored XSS. CWE-79 is the narrowest defensible mapping.
Attack pattern rationale
- CAPEC-64 The attack pattern involves storing a malicious payload (a javascript: URL) in a persistent data field (galaxy cluster source) that is later rendered in a web page, executing script in the victim's browser upon interaction. This is a textbook persistent/stored XSS. CAPEC-64 is the closest and most precise match in the CAPEC catalog.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 26 commits after fix); the exact first affected release is not stated in the patch.
- PR:L assumes galaxy editor privileges are a non-admin, role-based permission; the exact privilege model is not detailed in the patch.
- UI:A assumes the victim must actively click the rendered link; passive rendering without click does not execute the script.
- The CAPEC-64 mapping is the closest available pattern for stored XSS; no CAPEC specifically covers URI-scheme-based stored XSS, so CAPEC-64 is the best fit.
- The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103388",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:58:39.451751Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:06.980Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"GalaxyClusters view (default theme)",
"GalaxyClusters view (Overmind theme)"
],
"product": "MISP",
"programFiles": [
"app/View/GalaxyClusters/view.ctp",
"app/View/Themed/Overmind/Elements/GalaxyClusters/View/galaxy_clusters_general.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP\u0027s FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source.\u003c/p\u003e\u003cp\u003eWhen another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim\u0027s browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- Attacker must hold galaxy editor privileges (local or via sync).\u003c/p\u003e\u003cp\u003e- Victim must view the affected cluster and click the malicious link.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Stored cross-site scripting (XSS) in the victim\u0027s browser.\u003c/p\u003e\u003cp\u003e- Potential session theft, credential harvesting, or unauthorized actions within the MISP application.\u003c/p\u003e\u003cp\u003eAffected: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP\u0027s FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source.\n\nWhen another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim\u0027s browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim.\n\nPreconditions:\n\n- Attacker must hold galaxy editor privileges (local or via sync).\n\n- Victim must view the affected cluster and click the malicious link.\n\nImpact:\n\n- Stored cross-site scripting (XSS) in the victim\u0027s browser.\n\n- Potential session theft, credential harvesting, or unauthorized actions within the MISP application.\n\nAffected: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-64",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-64 XSS - Persistent"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input in Web Page (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:22:36.271Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/118528767"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme.\u003c/p\u003e"
}
],
"value": "The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme."
}
],
"title": "MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 26 commits after fix); the exact first affected release is not stated in the patch.",
"PR:L assumes galaxy editor privileges are a non-admin, role-based permission; the exact privilege model is not detailed in the patch.",
"UI:A assumes the victim must actively click the rendered link; passive rendering without click does not execute the script.",
"The CAPEC-64 mapping is the closest available pattern for stored XSS; no CAPEC specifically covers URI-scheme-based stored XSS, so CAPEC-64 is the best fit.",
"The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-64",
"rationale": "The attack pattern involves storing a malicious payload (a javascript: URL) in a persistent data field (galaxy cluster source) that is later rendered in a web page, executing script in the victim\u0027s browser upon interaction. This is a textbook persistent/stored XSS. CAPEC-64 is the closest and most precise match in the CAPEC catalog."
}
],
"commit": "11852876773554d79ff57937a235d18a1e4473dc",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N \u2013 MISP is a web application accessed over the network. AC:L \u2013 no race conditions or special environment needed; storing a javascript: URL is straightforward. AT:N \u2013 no manipulation of the attack target required. PR:L \u2013 attacker needs galaxy editor privileges (authenticated, non-admin role). UI:A \u2013 victim must click the malicious link for script execution. VC/VI/VA:N \u2013 the MISP server itself is not directly compromised; impact is on the victim\u0027s browser. SC:H \u2013 attacker can read cookies, session tokens, and manipulate the DOM in the victim\u0027s session. SI:H \u2013 attacker can perform actions on behalf of the victim within MISP. SA:N \u2013 no direct compromise of the application\u0027s security controls or system integrity.",
"fixSummary": "The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme.",
"generatedAt": "2026-09-30T14:12:32.112077Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "b68dbd6726929ff1680daeae2a273fc346e7075d7ded36195994315c19ccf278",
"patchSummary": "Two view templates are modified. In app/View/GalaxyClusters/view.ctp, the source value is extracted into a local variable and the conditional for rendering an anchor tag now requires both FILTER_VALIDATE_URL and a preg_match against /^https?:\\/\\//i. In app/View/Themed/Overmind/Elements/GalaxyClusters/View/galaxy_clusters_general.ctp, the same preg_match guard is added to the existing FILTER_VALIDATE_URL check. Net effect: only http(s) URLs produce a clickable link; all other values (including javascript:) are rendered as plain escaped text.",
"patchTruncated": false,
"patches": [
{
"commit": "11852876773554d79ff57937a235d18a1e4473dc",
"patchSha256": "b68dbd6726929ff1680daeae2a273fc346e7075d7ded36195994315c19ccf278",
"source": "https://github.com/MISP/MISP/commit/118528767.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/118528767.patch",
"subject": "fix: [security] Link a galaxy cluster source only when it is"
}
],
"source": "https://github.com/MISP/MISP/commit/118528767.patch",
"subject": "fix: [security] Link a galaxy cluster source only when it is",
"tagVersionBoundary": {
"commits_after_fix": 26,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The application renders user-controlled data (the galaxy cluster source field) into an HTML anchor tag without restricting the URI scheme to safe values. Although output is HTML-escaped via h(), the href attribute still accepts javascript: URIs, resulting in stored XSS. CWE-79 is the narrowest defensible mapping."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20256"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103388",
"datePublished": "2026-09-30T14:22:36.271Z",
"dateReserved": "2026-09-30T14:22:32.098Z",
"dateUpdated": "2026-09-30T15:28:06.980Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103321 (GCVE-0-2026-103321)
Vulnerability from cvelistv5 – Published: 2026-09-30 12:19 – Updated: 2026-09-30 12:44| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/92c7ccc43 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 11:21 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/92c7ccc43.patch
0ecb893de300… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
92c7ccc4398a
|
fix: [security] Validate the event graph preview and stop | 0ecb893de300… |
Fix summary
The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.
Patch summary
In app/Model/EventGraph.php, a new validation rule is added for the preview_img field requiring it to match the regex /^data:image\/png;base64,[A-Za-z0-9+\/]*={0,2}$/ (allowing empty). In app/webroot/js/event-graph.js, two occurrences of string-concatenated img tag construction (return '<img ... src="' + value + '" />') are replaced with jQuery DOM construction using $('<img ...>').prop('src', value), which sets the attribute safely without HTML parsing.
CVSS rationale
AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special conditions required; storing a crafted value and viewing the graph is straightforward. AT:N: no manipulation of the attack target needed. PR:L: attacker needs a low-privilege authenticated MISP account to create/modify an event graph. UI:P: the victim passively triggers the XSS by viewing the event graph preview (hovering a button), a normal workflow action. VC/VI/VA:N: the MISP server itself is not compromised; the impact is in the victim's browser. SC:H: the attacker can read cookies, tokens, and data in the victim's session. SI:H: the attacker can perform authenticated actions as the victim. SA:N: no availability impact on the victim's system.
Weakness rationale
- CWE-79 The stored preview_img value was rendered into an HTML attribute via string concatenation without sufficient neutralization, enabling script injection in the victim's browser. This is a textbook stored XSS.
- CWE-20 The server accepted and persisted the preview_img field without any format validation, allowing arbitrary content to be stored and later rendered. The fix adds a strict regex validation rule.
Attack pattern rationale
- CAPEC-1 The patch directly addresses a stored XSS where attacker-controlled data is rendered into a web page without proper encoding or validation. CAPEC-1 is the canonical attack pattern for XSS and is the closest match. No uncertainty in this mapping; the commit message explicitly identifies the issue as stored XSS.
Assumptions to verify
- The affected version range is inferred from the tag_version_boundary (v2.5.48 with 43 commits after the fix); the exact fixed release version is not stated in the patch metadata.
- PR:L assumes the attacker needs at least a basic authenticated MISP account to create or modify an event graph entry; the patch does not specify the exact permission level required.
- UI:P assumes the victim triggers the XSS by viewing the event graph preview as part of normal workflow (hovering the plot button), which is a passive interaction rather than an active click on a crafted link.
- The CAPEC-1 mapping is direct and unambiguous given the explicit stored XSS identification in the commit message.
- The Co-Authored-By line referencing Claude Opus 4.8 is treated as a tool credit per the commit metadata; it is not a human contributor.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103321",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T12:44:13.205587Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T12:44:22.064Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"EventGraph model",
"event-graph.js client-side rendering"
],
"product": "MISP",
"programFiles": [
"app/Model/EventGraph.php",
"app/webroot/js/event-graph.js"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\u003c/p\u003e\u003cp\u003eThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element\u0027s src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated MISP user with the ability to create or modify an event graph entry.\u003c/p\u003e\u003cp\u003e- A second user (the victim) who views the event graph and triggers the preview popover.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\u003c/p\u003e\u003cp\u003e- Potential theft of session tokens, cookies, or sensitive data accessible to the victim\u0027s browser.\u003c/p\u003e\u003cp\u003e- Potential for performing actions on behalf of the victim within the MISP application.\u003c/p\u003e\u003cp\u003eAffected: MISP versions prior to the fix (commit applied after v2.5.48).\u003c/p\u003e"
}
],
"value": "MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\n\nThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element\u0027s src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\n\nPreconditions:\n\n- An authenticated MISP user with the ability to create or modify an event graph entry.\n\n- A second user (the victim) who views the event graph and triggers the preview popover.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\n\n- Potential theft of session tokens, cookies, or sensitive data accessible to the victim\u0027s browser.\n\n- Potential for performing actions on behalf of the victim within the MISP application.\n\nAffected: MISP versions prior to the fix (commit applied after v2.5.48)."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting (XSS)"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T12:19:01.829Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/92c7ccc43"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML."
}
],
"title": "MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag_version_boundary (v2.5.48 with 43 commits after the fix); the exact fixed release version is not stated in the patch metadata.",
"PR:L assumes the attacker needs at least a basic authenticated MISP account to create or modify an event graph entry; the patch does not specify the exact permission level required.",
"UI:P assumes the victim triggers the XSS by viewing the event graph preview as part of normal workflow (hovering the plot button), which is a passive interaction rather than an active click on a crafted link.",
"The CAPEC-1 mapping is direct and unambiguous given the explicit stored XSS identification in the commit message.",
"The Co-Authored-By line referencing Claude Opus 4.8 is treated as a tool credit per the commit metadata; it is not a human contributor."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The patch directly addresses a stored XSS where attacker-controlled data is rendered into a web page without proper encoding or validation. CAPEC-1 is the canonical attack pattern for XSS and is the closest match. No uncertainty in this mapping; the commit message explicitly identifies the issue as stored XSS."
}
],
"commit": "92c7ccc4398a64e61699bd79fb4010703616fc59",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special conditions required; storing a crafted value and viewing the graph is straightforward. AT:N: no manipulation of the attack target needed. PR:L: attacker needs a low-privilege authenticated MISP account to create/modify an event graph. UI:P: the victim passively triggers the XSS by viewing the event graph preview (hovering a button), a normal workflow action. VC/VI/VA:N: the MISP server itself is not compromised; the impact is in the victim\u0027s browser. SC:H: the attacker can read cookies, tokens, and data in the victim\u0027s session. SI:H: the attacker can perform authenticated actions as the victim. SA:N: no availability impact on the victim\u0027s system.",
"fixSummary": "The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.",
"generatedAt": "2026-09-30T11:21:27.655462Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "0ecb893de30056bc3f9609fcb8de43d60b1cedd6a1eea7d6aa53ef6d351d642a",
"patchSummary": "In app/Model/EventGraph.php, a new validation rule is added for the preview_img field requiring it to match the regex /^data:image\\/png;base64,[A-Za-z0-9+\\/]*={0,2}$/ (allowing empty). In app/webroot/js/event-graph.js, two occurrences of string-concatenated img tag construction (return \u0027\u003cimg ... src=\"\u0027 + value + \u0027\" /\u003e\u0027) are replaced with jQuery DOM construction using $(\u0027\u003cimg ...\u003e\u0027).prop(\u0027src\u0027, value), which sets the attribute safely without HTML parsing.",
"patchTruncated": false,
"patches": [
{
"commit": "92c7ccc4398a64e61699bd79fb4010703616fc59",
"patchSha256": "0ecb893de30056bc3f9609fcb8de43d60b1cedd6a1eea7d6aa53ef6d351d642a",
"source": "https://github.com/MISP/MISP/commit/92c7ccc43.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/92c7ccc43.patch",
"subject": "fix: [security] Validate the event graph preview and stop"
}
],
"source": "https://github.com/MISP/MISP/commit/92c7ccc43.patch",
"subject": "fix: [security] Validate the event graph preview and stop",
"tagVersionBoundary": {
"commits_after_fix": 43,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The stored preview_img value was rendered into an HTML attribute via string concatenation without sufficient neutralization, enabling script injection in the victim\u0027s browser. This is a textbook stored XSS."
},
{
"cweId": "CWE-20",
"rationale": "The server accepted and persisted the preview_img field without any format validation, allowing arbitrary content to be stored and later rendered. The fix adds a strict regex validation rule."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20294"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103321",
"datePublished": "2026-09-30T12:19:01.829Z",
"dateReserved": "2026-09-30T12:18:54.232Z",
"dateUpdated": "2026-09-30T12:44:22.064Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103239 (GCVE-0-2026-103239)
Vulnerability from cvelistv5 – Published: 2026-09-30 10:16 – Updated: 2026-09-30 16:50| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/96f735e7b | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 09:58 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/96f735e7b.patch
67f9b5741b88… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
96f735e7b5d9
|
fix: [security] Tag collection saves no longer write sibling | 67f9b5741b88… |
Fix summary
The fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path.
Patch summary
In TagCollectionsController.php, both addWithTags() and editWithTags() were modified. The full $this->request->data is no longer passed to saveAssociated(). Instead, only the TagCollection key is extracted from the request. The saveAssociated() call is replaced with a plain save() for the collection, followed by an explicit loop that creates and saves each TagCollectionTag row individually. In editWithTags(), the tag rewrite logic is restructured to delete existing tag associations and re-insert them after the collection save. REST success/failure response handling is added to both methods.
CVSS rationale
The vulnerability is exploitable over the network (AV:N) with low complexity (AC:L) by simply adding extra fields to a legitimate tag collection request. No special attack conditions are required (AT:N). The attacker needs an authenticated account with the tag editor permission (PR:L). No user interaction is needed (UI:N). The primary impact is on integrity (VI:H) because the attacker can create or modify User and Organisation records to escalate to site admin. Modifications can be made so data can be see (VC:H) but no availability impact (VA:N). No subsequent component is affected (SC:N, SI:N, SA:N).
Weakness rationale
- CWE-284 A user with only tag editor permissions was able to write to User and Organisation records through the bulk-association save, bypassing the intended access control boundaries. The authorization model did not restrict which associated models could be persisted.
- CWE-862 The saveAssociated() call did not enforce per-model authorization checks, allowing any associated model data in the payload to be written regardless of the caller's permissions for those models.
Attack pattern rationale
- CAPEC-126 The attacker tampers with the HTTP request by injecting additional model fields (User, Organisation) into the tag collection payload. The application's bulk-save logic processes these unexpected parameters without filtering, leading to unauthorized record creation or modification. This is the closest CAPEC to the observed attack: adding extra parameters to a legitimate request to trigger unintended side effects.
- CAPEC-1 The application accepted the entire request body without validating or restricting which model keys were present before passing it to the persistence layer. This is a secondary mapping; CAPEC-126 is more specific to the parameter-injection attack vector observed here.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48 with 24 commits after fix), suggesting the fix is included in v2.5.48. No explicit version range is stated in the patch itself.
- The privilege level required is assumed to be 'perm_tag_editor' based on the commit message; the exact permission model and whether other roles are affected is not fully verifiable from the patch alone.
- CAPEC-126 (Parameter Tampering) is selected as the closest match; the attack is more precisely a mass-assignment / sibling-model injection via an ORM bulk-save, for which no exact CAPEC exists. CAPEC-126 is the best available approximation.
- The CVSS assumes the attacker can reach the MISP web interface over the network and holds a valid session with tag editor permissions. No multi-step or race-condition requirements are evident.
- The Co-Authored-By line references an AI assistant (Claude Opus 4.8); it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103239",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:49:52.252773Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:50:57.400Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"TagCollectionsController"
],
"product": "MISP",
"programFiles": [
"app/Controller/TagCollectionsController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload.\u003c/p\u003e\u003cp\u003eA user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated account with the tag editor permission (perm_tag_editor)\u003c/p\u003e\u003cp\u003e- Network access to the MISP instance\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Unauthorized creation or modification of User and Organisation records\u003c/p\u003e\u003cp\u003e- Privilege escalation from tag editor to site administrator\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt; 2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload.\n\nA user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator.\n\nPreconditions:\n\n- An authenticated account with the tag editor permission (perm_tag_editor)\n\n- Network access to the MISP instance\n\nImpact:\n\n- Unauthorized creation or modification of User and Organisation records\n\n- Privilege escalation from tag editor to site administrator\n\nAffected versions: \u003c 2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Parameter Tampering"
}
]
},
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Improper Input Validation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "CWE-284 Improper Access Control",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T10:16:18.835Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/96f735e7b"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path.\u003c/p\u003e"
}
],
"value": "The fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path."
}
],
"title": "MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48 with 24 commits after fix), suggesting the fix is included in v2.5.48. No explicit version range is stated in the patch itself.",
"The privilege level required is assumed to be \u0027perm_tag_editor\u0027 based on the commit message; the exact permission model and whether other roles are affected is not fully verifiable from the patch alone.",
"CAPEC-126 (Parameter Tampering) is selected as the closest match; the attack is more precisely a mass-assignment / sibling-model injection via an ORM bulk-save, for which no exact CAPEC exists. CAPEC-126 is the best available approximation.",
"The CVSS assumes the attacker can reach the MISP web interface over the network and holds a valid session with tag editor permissions. No multi-step or race-condition requirements are evident.",
"The Co-Authored-By line references an AI assistant (Claude Opus 4.8); it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The attacker tampers with the HTTP request by injecting additional model fields (User, Organisation) into the tag collection payload. The application\u0027s bulk-save logic processes these unexpected parameters without filtering, leading to unauthorized record creation or modification. This is the closest CAPEC to the observed attack: adding extra parameters to a legitimate request to trigger unintended side effects."
},
{
"capecId": "CAPEC-1",
"rationale": "The application accepted the entire request body without validating or restricting which model keys were present before passing it to the persistence layer. This is a secondary mapping; CAPEC-126 is more specific to the parameter-injection attack vector observed here."
}
],
"commit": "96f735e7b5d9e28ea2eaf3d8a02ab800bad5c9ed",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "The vulnerability is exploitable over the network (AV:N) with low complexity (AC:L) by simply adding extra fields to a legitimate tag collection request. No special attack conditions are required (AT:N). The attacker needs an authenticated account with the tag editor permission (PR:L). No user interaction is needed (UI:N). The primary impact is on integrity (VI:H) because the attacker can create or modify User and Organisation records to escalate to site admin. Modifications can be made so data can be see (VC:H) but no availability impact (VA:N). No subsequent component is affected (SC:N, SI:N, SA:N).",
"fixSummary": "The fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path.",
"generatedAt": "2026-09-30T09:58:24.508004Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "67f9b5741b88384cd891423b2a8b9f5c8e071b5895b93eb337a16c7f780ee88c",
"patchSummary": "In TagCollectionsController.php, both addWithTags() and editWithTags() were modified. The full $this-\u003erequest-\u003edata is no longer passed to saveAssociated(). Instead, only the TagCollection key is extracted from the request. The saveAssociated() call is replaced with a plain save() for the collection, followed by an explicit loop that creates and saves each TagCollectionTag row individually. In editWithTags(), the tag rewrite logic is restructured to delete existing tag associations and re-insert them after the collection save. REST success/failure response handling is added to both methods.",
"patchTruncated": false,
"patches": [
{
"commit": "96f735e7b5d9e28ea2eaf3d8a02ab800bad5c9ed",
"patchSha256": "67f9b5741b88384cd891423b2a8b9f5c8e071b5895b93eb337a16c7f780ee88c",
"source": "https://github.com/MISP/MISP/commit/96f735e7b.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/96f735e7b.patch",
"subject": "fix: [security] Tag collection saves no longer write sibling"
}
],
"source": "https://github.com/MISP/MISP/commit/96f735e7b.patch",
"subject": "fix: [security] Tag collection saves no longer write sibling",
"tagVersionBoundary": {
"commits_after_fix": 24,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-284",
"rationale": "A user with only tag editor permissions was able to write to User and Organisation records through the bulk-association save, bypassing the intended access control boundaries. The authorization model did not restrict which associated models could be persisted."
},
{
"cweId": "CWE-862",
"rationale": "The saveAssociated() call did not enforce per-model authorization checks, allowing any associated model data in the payload to be written regardless of the caller\u0027s permissions for those models."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20019"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103239",
"datePublished": "2026-09-30T10:16:18.835Z",
"dateReserved": "2026-09-30T10:16:15.941Z",
"dateUpdated": "2026-09-30T16:50:57.400Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103237 (GCVE-0-2026-103237)
Vulnerability from cvelistv5 – Published: 2026-09-30 09:56 – Updated: 2026-09-30 17:08| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/9485ae40d | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 09:24 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/9485ae40d.patch
03af388a5ac0… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
9485ae40d334
|
fix: [security] A nested model alias key no longer selects | 03af388a5ac0… |
Fix summary
The fix introduces a defensive save() override in the base model class that refuses to persist any record where the data array simultaneously contains a nested key matching the model alias and other top-level scalar fields, logging a warning and returning false. Additionally, all code paths that sanitize and save records (free-text import, module result processing, object delta merge, attribute bulk edit, sighting capture, shadow attribute proposal, event report creation) now explicitly unset the nested alias key from the data array before calling save(), ensuring the ORM cannot be redirected to an attacker-chosen row. Controller-level request reshaping was also corrected to avoid creating self-referencing data structures.
Patch summary
Added a save() override in AppModel.php that detects and rejects ambiguous payloads containing both a nested model-alias key and outer scalars. Added unset($data[$this->alias]) calls in Event.php (free-text, module results, object attribute save), MispAttribute.php (saveAttributes, captureAttribute, editAttributeBulk), MispObject.php (deltaMerge, editObject), ShadowAttribute.php (__preCaptureMassage), and Sighting.php (captureSightings) to strip the nested alias key before save. Changed six controller files to use $this->request->data = array('Model' => $this->request->data) instead of $this->request->data['Model'] = $this->request->data, preventing self-referencing structures. Added a new regression test suite (tests/testregressions.py) with cross-tenant attack scenarios and wired it into the CI workflow.
CVSS rationale
AV:N - MISP is a network-accessible web application. AC:L - The attack requires only crafting a request with a nested alias key; no race condition or complex state is needed. AT:N - No in-transit tampering required. PR:L - An authenticated user with basic write permission (perm_add) suffices; no admin or sync role needed. UI:N - No victim interaction required. VC:N - The attacker does not gain new read access; the impact is on data they can already partially see or infer. VI:H - The attacker can overwrite, re-parent, or soft-delete rows in the same instance, causing high integrity loss to the vulnerable component's data. VA:N - Soft-delete is a state change (integrity) rather than a service disruption. SC:N - No impact on separate components' confidentiality. SI:H - The cross-tenant nature means integrity of other organizations' data (a separate security scope) is compromised. SA:N - No security mechanism is weakened.
Weakness rationale
- CWE-639 The attacker controls the row identifier (id) inside the nested alias block, which the ORM uses to select the target row. The application's authorization and sanitization (id stripping, event_id pinning) is applied to the outer record and is bypassed because the ORM binds to the inner record. This is a direct case of a user-controlled key selecting an unauthorized resource.
- CWE-20 The application fails to validate or strip the nested model-alias key from user-supplied data before passing it to the ORM. The ORM's set() method interprets this key as the record to save, contradicting the application's intent. The absence of validation on this structural aspect of the input is the root cause.
Attack pattern rationale
- CAPEC-24 The attacker tampers with the structure of request parameters by injecting a nested key matching the model alias, causing the ORM to target a different row than the application intended. The outer parameters (sanitized id, pinned event_id) are effectively ignored in favor of the attacker-controlled inner parameters. This is a structural parameter tampering attack exploiting the ORM's data-binding semantics. The mapping is the closest available CAPEC; no more specific pattern for ORM-level key injection exists in the CAPEC catalog.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48); the exact last affected release and first fixed release are not explicitly stated in the patch.
- PR:L assumes the attacker needs only a basic authenticated account with perm_add; the regression tests confirm a non-admin, non-sync role suffices, but the minimum permission set is not exhaustively enumerated in the patch.
- VA:N assumes soft-delete is treated as an integrity impact (data state change) rather than an availability impact; if the organization considers soft-deleted records as unavailable, VA could be raised to L.
- CAPEC-24 (Parameter Tampering) is the closest available pattern; the specific ORM-level key-binding manipulation does not have a dedicated CAPEC entry, so the mapping is approximate.
- The Co-Authored-By line references an AI tool (Claude Opus 5); it is listed as a tool credit, not a human remediation developer, per CVE credit role semantics.
- The commit date is 2026-09-25; the vulnerability may have existed for an unknown duration prior to reporting.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | high | 6 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103237",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T17:08:29.034418Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T17:08:51.346Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"AttributesController",
"EventReportsController",
"EventsController",
"ObjectReferencesController",
"ShadowAttributesController",
"UsersController",
"AppModel",
"Event model",
"MispAttribute model",
"MispObject model",
"ShadowAttribute model",
"Sighting model"
],
"product": "MISP",
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the flat record by stripping the primary key and pinning the event_id or object_id to the caller\u0027s context. However, the underlying ORM\u0027s set() method gives priority to a nested key whose name matches the model alias and discards the outer scalar fields.\u003c/p\u003e\u003cp\u003eAn authenticated user with basic write permissions can exploit this by embedding a nested block under the model alias key inside their request. The sanitization logic (id removal, event_id pinning) is applied to the outer record, but the ORM binds to the inner record instead, which carries an attacker-chosen id and event_id. This allows the attacker to overwrite, re-parent, or soft-delete rows belonging to other organizations or events they have no read access to.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Cross-tenant data integrity compromise (attribute values rewritten, objects re-parented to attacker events, rows soft-deleted)\u003c/p\u003e\u003cp\u003e- Affects multiple entity types: Attribute, Object, EventReport, Sighting, AttributeTag, ShadowAttribute\u003c/p\u003e\u003cp\u003e- Requires only a low-privilege authenticated account with perm_add\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the flat record by stripping the primary key and pinning the event_id or object_id to the caller\u0027s context. However, the underlying ORM\u0027s set() method gives priority to a nested key whose name matches the model alias and discards the outer scalar fields.\n\nAn authenticated user with basic write permissions can exploit this by embedding a nested block under the model alias key inside their request. The sanitization logic (id removal, event_id pinning) is applied to the outer record, but the ORM binds to the inner record instead, which carries an attacker-chosen id and event_id. This allows the attacker to overwrite, re-parent, or soft-delete rows belonging to other organizations or events they have no read access to.\n\nImpact:\n\n- Cross-tenant data integrity compromise (attribute values rewritten, objects re-parented to attacker events, rows soft-deleted)\n\n- Affects multiple entity types: Attribute, Object, EventReport, Sighting, AttributeTag, ShadowAttribute\n\n- Requires only a low-privilege authenticated account with perm_add\n\nAffected versions: \u003c2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-24",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-24 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T09:56:35.584Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/9485ae40d"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix introduces a defensive save() override in the base model class that refuses to persist any record where the data array simultaneously contains a nested key matching the model alias and other top-level scalar fields, logging a warning and returning false. Additionally, all code paths that sanitize and save records (free-text import, module result processing, object delta merge, attribute bulk edit, sighting capture, shadow attribute proposal, event report creation) now explicitly unset the nested alias key from the data array before calling save(), ensuring the ORM cannot be redirected to an attacker-chosen row. Controller-level request reshaping was also corrected to avoid creating self-referencing data structures.\u003c/p\u003e"
}
],
"value": "The fix introduces a defensive save() override in the base model class that refuses to persist any record where the data array simultaneously contains a nested key matching the model alias and other top-level scalar fields, logging a warning and returning false. Additionally, all code paths that sanitize and save records (free-text import, module result processing, object delta merge, attribute bulk edit, sighting capture, shadow attribute proposal, event report creation) now explicitly unset the nested alias key from the data array before calling save(), ensuring the ORM cannot be redirected to an attacker-chosen row. Controller-level request reshaping was also corrected to avoid creating self-referencing data structures."
}
],
"title": "MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48); the exact last affected release and first fixed release are not explicitly stated in the patch.",
"PR:L assumes the attacker needs only a basic authenticated account with perm_add; the regression tests confirm a non-admin, non-sync role suffices, but the minimum permission set is not exhaustively enumerated in the patch.",
"VA:N assumes soft-delete is treated as an integrity impact (data state change) rather than an availability impact; if the organization considers soft-deleted records as unavailable, VA could be raised to L.",
"CAPEC-24 (Parameter Tampering) is the closest available pattern; the specific ORM-level key-binding manipulation does not have a dedicated CAPEC entry, so the mapping is approximate.",
"The Co-Authored-By line references an AI tool (Claude Opus 5); it is listed as a tool credit, not a human remediation developer, per CVE credit role semantics.",
"The commit date is 2026-09-25; the vulnerability may have existed for an unknown duration prior to reporting."
],
"capecRationale": [
{
"capecId": "CAPEC-24",
"rationale": "The attacker tampers with the structure of request parameters by injecting a nested key matching the model alias, causing the ORM to target a different row than the application intended. The outer parameters (sanitized id, pinned event_id) are effectively ignored in favor of the attacker-controlled inner parameters. This is a structural parameter tampering attack exploiting the ORM\u0027s data-binding semantics. The mapping is the closest available CAPEC; no more specific pattern for ORM-level key injection exists in the CAPEC catalog."
}
],
"commit": "9485ae40d334471882e3bd246651acaa68feef34",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"cvssRationale": "AV:N - MISP is a network-accessible web application. AC:L - The attack requires only crafting a request with a nested alias key; no race condition or complex state is needed. AT:N - No in-transit tampering required. PR:L - An authenticated user with basic write permission (perm_add) suffices; no admin or sync role needed. UI:N - No victim interaction required. VC:N - The attacker does not gain new read access; the impact is on data they can already partially see or infer. VI:H - The attacker can overwrite, re-parent, or soft-delete rows in the same instance, causing high integrity loss to the vulnerable component\u0027s data. VA:N - Soft-delete is a state change (integrity) rather than a service disruption. SC:N - No impact on separate components\u0027 confidentiality. SI:H - The cross-tenant nature means integrity of other organizations\u0027 data (a separate security scope) is compromised. SA:N - No security mechanism is weakened.",
"fixSummary": "The fix introduces a defensive save() override in the base model class that refuses to persist any record where the data array simultaneously contains a nested key matching the model alias and other top-level scalar fields, logging a warning and returning false. Additionally, all code paths that sanitize and save records (free-text import, module result processing, object delta merge, attribute bulk edit, sighting capture, shadow attribute proposal, event report creation) now explicitly unset the nested alias key from the data array before calling save(), ensuring the ORM cannot be redirected to an attacker-chosen row. Controller-level request reshaping was also corrected to avoid creating self-referencing data structures.",
"generatedAt": "2026-09-30T09:24:37.816321Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 6,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "03af388a5ac0d93cebef902e0050aa8496aae8d88d1496b80abc0b9a929cb39a",
"patchSummary": "Added a save() override in AppModel.php that detects and rejects ambiguous payloads containing both a nested model-alias key and outer scalars. Added unset($data[$this-\u003ealias]) calls in Event.php (free-text, module results, object attribute save), MispAttribute.php (saveAttributes, captureAttribute, editAttributeBulk), MispObject.php (deltaMerge, editObject), ShadowAttribute.php (__preCaptureMassage), and Sighting.php (captureSightings) to strip the nested alias key before save. Changed six controller files to use $this-\u003erequest-\u003edata = array(\u0027Model\u0027 =\u003e $this-\u003erequest-\u003edata) instead of $this-\u003erequest-\u003edata[\u0027Model\u0027] = $this-\u003erequest-\u003edata, preventing self-referencing structures. Added a new regression test suite (tests/testregressions.py) with cross-tenant attack scenarios and wired it into the CI workflow.",
"patchTruncated": false,
"patches": [
{
"commit": "9485ae40d334471882e3bd246651acaa68feef34",
"patchSha256": "03af388a5ac0d93cebef902e0050aa8496aae8d88d1496b80abc0b9a929cb39a",
"source": "https://github.com/MISP/MISP/commit/9485ae40d.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/9485ae40d.patch",
"subject": "fix: [security] A nested model alias key no longer selects"
}
],
"source": "https://github.com/MISP/MISP/commit/9485ae40d.patch",
"subject": "fix: [security] A nested model alias key no longer selects",
"tagVersionBoundary": {
"commits_after_fix": 23,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-639",
"rationale": "The attacker controls the row identifier (id) inside the nested alias block, which the ORM uses to select the target row. The application\u0027s authorization and sanitization (id stripping, event_id pinning) is applied to the outer record and is bypassed because the ORM binds to the inner record. This is a direct case of a user-controlled key selecting an unauthorized resource."
},
{
"cweId": "CWE-20",
"rationale": "The application fails to validate or strip the nested model-alias key from user-supplied data before passing it to the ORM. The ORM\u0027s set() method interprets this key as the record to save, contradicting the application\u0027s intent. The absence of validation on this structural aspect of the input is the root cause."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20280"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103237",
"datePublished": "2026-09-30T09:56:35.584Z",
"dateReserved": "2026-09-30T09:56:33.891Z",
"dateUpdated": "2026-09-30T17:08:51.346Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103235 (GCVE-0-2026-103235)
Vulnerability from cvelistv5 – Published: 2026-09-30 09:09 – Updated: 2026-09-30 14:32| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/d1f5684f9 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 07:37 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/d1f5684f9.patch
f478751165e6… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
d1f5684f9a19
|
fix: [security] Delegation requests stay bound to the event | f478751165e6… |
Fix summary
The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.
Patch summary
In EventDelegationsController::delegateEvent(), the code previously saved $this->request->data['EventDelegation'] directly after setting a few fields. The fix replaces this with an explicit allow-list array containing only event_id (from the authorized URL event), requester_org_id (from the session), org_id (resolved from submitted UUID), message, distribution, and sharing_group_id. The primary key id is never included. A regression test class DelegationRequestRetargeting was added to verify that injecting a nested EventDelegation with a foreign id and event_id does not grant read access to the victim event.
CVSS rationale
Network vector: MISP is a web application accessible over HTTP. Low complexity: a single crafted POST request suffices. No attack target manipulation. Low privileges: requires an authenticated user with perm_delegate. No user interaction: read access is granted immediately upon creating the retargeted delegation. High confidentiality: grants read access to any event on the instance. High integrity: overwrites existing delegation records and can transfer event ownership. No availability impact without victim acceptance. Scope change (SC:H, SI:H): the vulnerability crosses organisational boundaries, affecting data owned by other organisations. No sub-system availability impact.
Weakness rationale
- CWE-915 The application persisted the entire user-submitted record including fields (id, event_id) that should not be attacker-controllable, allowing mass assignment of sensitive fields to retarget the delegation.
- CWE-639 The authorization check validated only the event in the URL, but the attacker-supplied primary key or event_id in the payload redirected the operation to a different record, bypassing the intended authorization boundary.
Attack pattern rationale
- CAPEC-12 The attacker manipulates hidden or additional fields in a form/API request (injecting id and event_id into the EventDelegation payload) to modify data beyond what the application intended to accept. This is the canonical mass assignment pattern: the server processes user-supplied fields it should have ignored. The mapping is direct and well-supported by the patch evidence.
Assumptions to verify
- The affected version boundary (< 2.5.48) is inferred from the tag_version_boundary metadata showing v2.5.48 as the nearest tag with 22 commits after the fix; the exact last affected release is not explicitly stated in the patch.
- PR:L assumes the attacker needs only the perm_delegate permission, which is a non-admin role; the exact role configuration may vary by deployment.
- VA:N assumes the availability impact (deletion of the original event) requires victim acceptance and is therefore not a direct availability impact of the vulnerability itself.
- The CAPEC-12 mapping is the closest standard pattern; the vulnerability also has IDOR characteristics (CWE-639) but CAPEC-12 best captures the mass-assignment mechanism demonstrated in the patch.
- The MISP.delegation server setting must be enabled for the vulnerability to be exploitable; this is a deployment configuration assumption.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103235",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:32:35.584208Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:32:45.581Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"EventDelegationsController"
],
"product": "MISP",
"programFiles": [
"app/Controller/EventDelegationsController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\u003c/p\u003e\u003cp\u003eAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated user with the delegation permission (perm_delegate)\u003c/p\u003e\u003cp\u003e- The MISP.delegation server setting must be enabled\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Confidentiality: read access to any event on the instance\u003c/p\u003e\u003cp\u003e- Integrity: overwriting existing delegation records and transferring event ownership\u003c/p\u003e\u003cp\u003eAffected versions: MISP \u0026lt; 2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\n\nAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\n\nPreconditions:\n\n- An authenticated user with the delegation permission (perm_delegate)\n\n- The MISP.delegation server setting must be enabled\n\nImpact:\n\n- Confidentiality: read access to any event on the instance\n\n- Integrity: overwriting existing delegation records and transferring event ownership\n\nAffected versions: MISP \u003c 2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-12",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-12 Mass Assignment"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T09:12:56.533Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/d1f5684f9"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.\u003c/p\u003e"
}
],
"value": "The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary (\u003c 2.5.48) is inferred from the tag_version_boundary metadata showing v2.5.48 as the nearest tag with 22 commits after the fix; the exact last affected release is not explicitly stated in the patch.",
"PR:L assumes the attacker needs only the perm_delegate permission, which is a non-admin role; the exact role configuration may vary by deployment.",
"VA:N assumes the availability impact (deletion of the original event) requires victim acceptance and is therefore not a direct availability impact of the vulnerability itself.",
"The CAPEC-12 mapping is the closest standard pattern; the vulnerability also has IDOR characteristics (CWE-639) but CAPEC-12 best captures the mass-assignment mechanism demonstrated in the patch.",
"The MISP.delegation server setting must be enabled for the vulnerability to be exploitable; this is a deployment configuration assumption."
],
"capecRationale": [
{
"capecId": "CAPEC-12",
"rationale": "The attacker manipulates hidden or additional fields in a form/API request (injecting id and event_id into the EventDelegation payload) to modify data beyond what the application intended to accept. This is the canonical mass assignment pattern: the server processes user-supplied fields it should have ignored. The mapping is direct and well-supported by the patch evidence."
}
],
"commit": "d1f5684f9a193ea0a8a4f7709703011aa69d9682",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"cvssRationale": "Network vector: MISP is a web application accessible over HTTP. Low complexity: a single crafted POST request suffices. No attack target manipulation. Low privileges: requires an authenticated user with perm_delegate. No user interaction: read access is granted immediately upon creating the retargeted delegation. High confidentiality: grants read access to any event on the instance. High integrity: overwrites existing delegation records and can transfer event ownership. No availability impact without victim acceptance. Scope change (SC:H, SI:H): the vulnerability crosses organisational boundaries, affecting data owned by other organisations. No sub-system availability impact.",
"fixSummary": "The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.",
"generatedAt": "2026-09-30T07:37:05.841152Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "f478751165e658f2b26822845ec034386d8a1740527cf30863792e9521f24611",
"patchSummary": "In EventDelegationsController::delegateEvent(), the code previously saved $this-\u003erequest-\u003edata[\u0027EventDelegation\u0027] directly after setting a few fields. The fix replaces this with an explicit allow-list array containing only event_id (from the authorized URL event), requester_org_id (from the session), org_id (resolved from submitted UUID), message, distribution, and sharing_group_id. The primary key id is never included. A regression test class DelegationRequestRetargeting was added to verify that injecting a nested EventDelegation with a foreign id and event_id does not grant read access to the victim event.",
"patchTruncated": false,
"patches": [
{
"commit": "d1f5684f9a193ea0a8a4f7709703011aa69d9682",
"patchSha256": "f478751165e658f2b26822845ec034386d8a1740527cf30863792e9521f24611",
"source": "https://github.com/MISP/MISP/commit/d1f5684f9.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/d1f5684f9.patch",
"subject": "fix: [security] Delegation requests stay bound to the event"
}
],
"source": "https://github.com/MISP/MISP/commit/d1f5684f9.patch",
"subject": "fix: [security] Delegation requests stay bound to the event",
"tagVersionBoundary": {
"commits_after_fix": 22,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-915",
"rationale": "The application persisted the entire user-submitted record including fields (id, event_id) that should not be attacker-controllable, allowing mass assignment of sensitive fields to retarget the delegation."
},
{
"cweId": "CWE-639",
"rationale": "The authorization check validated only the event in the URL, but the attacker-supplied primary key or event_id in the payload redirected the operation to a different record, bypassing the intended authorization boundary."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20227"
}
],
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103235",
"datePublished": "2026-09-30T09:09:36.761Z",
"dateReserved": "2026-09-30T09:09:33.466Z",
"dateUpdated": "2026-09-30T14:32:45.581Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97863 (GCVE-0-2026-97863)
Vulnerability from cvelistv5 – Published: 2026-09-25 08:03 – Updated: 2026-09-25 13:19- CWE-78 - Improper Neutralization of Special Elements used in a Command ("Command Injection")
| URL | Tags |
|---|---|
| https://github.com/misp/misp-modules/commit/625b5… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| misp | misp-modules |
Affected:
0 , ≤ 3.0.10
(semver)
|
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-25 07:48 - Model
qwen3.8:27b- Input
-
https://github.com/elhoim/misp-modules/commit/625b54908efbd6acc8343aa3370d401dd370e748.patch
9c34349775d0… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
625b54908efb
|
fix: [cisco_firesight_manager_ACL_rule_export] shell-escape | 9c34349775d0… |
Fix summary
All user-controlled and configuration values interpolated into the generated shell script are now passed through Python's shlex.quote() function, which produces a safely quoted string that cannot be broken out of by embedded shell metacharacters. For the JSON access-rule block that embeds multiple attribute values within a single shell assignment, the JSON content is first assembled as plain text and then the entire assembled string is shlex-quoted once, preventing stray quote characters from corrupting the outer quoting. The 'config' variable is now initialized to an empty dictionary before the conditional assignment, eliminating the NameError.
Patch summary
Added 'import shlex' at the top of the module. Replaced direct .format() interpolation of config values (fmc_ip_addr, fmc_login, fmc_pass, domain_id, acpolicy_id) with shlex.quote()-wrapped values. Refactored the BLOCK_JSON_TMPL to separate the JSON content template (BLOCK_JSON_CONTENT_TMPL) from the shell assignment template; the JSON content is formatted first with raw attribute values, then the resulting string is passed through shlex.quote() before being substituted into the shell assignment. Initialized 'config = {}' before the 'if "config" in request:' block to prevent NameError.
CVSS rationale
AV:N: The attacker submits crafted MISP attribute values over the network to a MISP instance. AC:L: Injecting a single-quote character into an attribute value is trivial and requires no race conditions or special timing. AT:N: No special data manipulation or prior access to the target system is needed beyond submitting an event. PR:L: The attacker needs only basic MISP user privileges to create or modify events/attributes. UI:A: The victim analyst must actively execute the generated .sh file for the injected commands to run. VC:N, VI:N, VA:N: The MISP instance itself is not directly compromised; the impact is on the downstream system where the script executes. SC:H: The injected commands can exfiltrate fireSIGHT Manager credentials and analyst system data. SI:H: Arbitrary command execution allows modification of ACL rules, system files, or other integrity-critical resources. SA:H: Injected commands can disrupt or destroy the analyst workstation or fireSIGHT Manager availability.
Weakness rationale
- CWE-78 The module constructs a shell script by interpolating untrusted values (MISP attribute values, configuration fields) into single-quoted shell strings without escaping. A single-quote character in any interpolated value breaks the quoting and allows arbitrary shell command injection. This is a textbook command injection via insufficient output encoding in a generated shell script.
Attack pattern rationale
- CAPEC-88 The attack pattern involves an attacker supplying input containing shell metacharacters (specifically a single quote) that is incorporated into a shell command or script without proper sanitization, resulting in execution of attacker-controlled commands. The patch confirms the vulnerable pattern: values are interpolated into single-quoted shell assignments, and the fix is to apply shlex.quote() to neutralize shell metacharacters. This is the closest and most specific CAPEC mapping for the observed vulnerability.
Assumptions to verify
- The CVSS UI metric is set to A (Active) because the victim analyst must deliberately execute the generated .sh file; CVSS v4.0 does not use the v3.x 'R' value.
- PR is set to L assuming the attacker holds a basic MISP user role sufficient to create or modify events and attributes; the patch does not specify exact role requirements.
- SC, SI, SA are rated H based on the potential for arbitrary command execution on the analyst workstation and the fireSIGHT Manager; actual impact depends on the analyst's local privileges and the fireSIGHT Manager's exposure.
- The CAPEC-88 mapping is the closest available pattern; the vulnerability is specifically an output-encoding failure in generated shell script rather than direct command-line injection, but CAPEC-88 is the narrowest defensible match.
- No specific affected or fixed version numbers are available from the patch metadata; the commit date (2026-08-31) is the only temporal anchor.
- The secondary NameError bug (config variable) is a minor denial-of-service issue included in the same patch but is not the primary security concern.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | high | 6 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97863",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T13:18:10.409406Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T13:19:52.508Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://github.com/MISP/misp-modules",
"defaultStatus": "unaffected",
"modules": [
"cisco_firesight_manager_ACL_rule_export"
],
"product": "misp-modules",
"programFiles": [
"misp_modules/modules/export_mod/cisco_firesight_manager_ACL_rule_export.py"
],
"repo": "https://github.com/misp/misp-modules",
"vendor": "misp",
"versions": [
{
"lessThanOrEqual": "3.0.10",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "elhoim"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values (IP address, login, password, domain ID, policy ID) and MISP attribute values (destination IPs, URLs, event info comments) directly into single-quoted shell string assignments without any escaping or sanitization. Because the values are placed inside single-quoted shell strings, any value containing a single-quote character (e.g., a crafted ip-dst or url attribute value submitted to MISP) breaks out of the quoting context, allowing an attacker to inject arbitrary shell commands into the exported script. A security analyst who subsequently executes the generated .sh file unmodified would run the injected commands with their own privileges, potentially exposing fireSIGHT Manager credentials, modifying ACL rules, or compromising the analyst workstation. Additionally, the module contained a secondary defect where the variable \u0027config\u0027 was only assigned inside a conditional block but referenced unconditionally afterward, causing a NameError (denial of service) when the request payload lacked a \u0027config\u0027 key. The vulnerability requires the attacker to have the ability to submit MISP events or attributes containing a single-quote character and the victim to execute the exported script. No authentication bypass is required beyond standard MISP event-submission privileges.\u003c/p\u003e"
}
],
"value": "The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values (IP address, login, password, domain ID, policy ID) and MISP attribute values (destination IPs, URLs, event info comments) directly into single-quoted shell string assignments without any escaping or sanitization. Because the values are placed inside single-quoted shell strings, any value containing a single-quote character (e.g., a crafted ip-dst or url attribute value submitted to MISP) breaks out of the quoting context, allowing an attacker to inject arbitrary shell commands into the exported script. A security analyst who subsequently executes the generated .sh file unmodified would run the injected commands with their own privileges, potentially exposing fireSIGHT Manager credentials, modifying ACL rules, or compromising the analyst workstation. Additionally, the module contained a secondary defect where the variable \u0027config\u0027 was only assigned inside a conditional block but referenced unconditionally afterward, causing a NameError (denial of service) when the request payload lacked a \u0027config\u0027 key. The vulnerability requires the attacker to have the ability to submit MISP events or attributes containing a single-quote character and the victim to execute the exported script. No authentication bypass is required beyond standard MISP event-submission privileges."
}
],
"impacts": [
{
"capecId": "CAPEC-88",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-88 Shell Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in a Command (\"Command Injection\")",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T09:50:00.869Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/misp/misp-modules/commit/625b54908efbd6acc8343aa3370d401dd370e748"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAll user-controlled and configuration values interpolated into the generated shell script are now passed through Python\u0027s shlex.quote() function, which produces a safely quoted string that cannot be broken out of by embedded shell metacharacters. For the JSON access-rule block that embeds multiple attribute values within a single shell assignment, the JSON content is first assembled as plain text and then the entire assembled string is shlex-quoted once, preventing stray quote characters from corrupting the outer quoting. The \u0027config\u0027 variable is now initialized to an empty dictionary before the conditional assignment, eliminating the NameError.\u003c/p\u003e"
}
],
"value": "All user-controlled and configuration values interpolated into the generated shell script are now passed through Python\u0027s shlex.quote() function, which produces a safely quoted string that cannot be broken out of by embedded shell metacharacters. For the JSON access-rule block that embeds multiple attribute values within a single shell assignment, the JSON content is first assembled as plain text and then the entire assembled string is shlex-quoted once, preventing stray quote characters from corrupting the outer quoting. The \u0027config\u0027 variable is now initialized to an empty dictionary before the conditional assignment, eliminating the NameError."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "misp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Module via Unescaped Attribute Values",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "none",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The CVSS UI metric is set to A (Active) because the victim analyst must deliberately execute the generated .sh file; CVSS v4.0 does not use the v3.x \u0027R\u0027 value.",
"PR is set to L assuming the attacker holds a basic MISP user role sufficient to create or modify events and attributes; the patch does not specify exact role requirements.",
"SC, SI, SA are rated H based on the potential for arbitrary command execution on the analyst workstation and the fireSIGHT Manager; actual impact depends on the analyst\u0027s local privileges and the fireSIGHT Manager\u0027s exposure.",
"The CAPEC-88 mapping is the closest available pattern; the vulnerability is specifically an output-encoding failure in generated shell script rather than direct command-line injection, but CAPEC-88 is the narrowest defensible match.",
"No specific affected or fixed version numbers are available from the patch metadata; the commit date (2026-08-31) is the only temporal anchor.",
"The secondary NameError bug (config variable) is a minor denial-of-service issue included in the same patch but is not the primary security concern."
],
"capecRationale": [
{
"capecId": "CAPEC-88",
"rationale": "The attack pattern involves an attacker supplying input containing shell metacharacters (specifically a single quote) that is incorporated into a shell command or script without proper sanitization, resulting in execution of attacker-controlled commands. The patch confirms the vulnerable pattern: values are interpolated into single-quoted shell assignments, and the fix is to apply shlex.quote() to neutralize shell metacharacters. This is the closest and most specific CAPEC mapping for the observed vulnerability."
}
],
"commit": "625b54908efbd6acc8343aa3370d401dd370e748",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "elhoim"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"cvssRationale": "AV:N: The attacker submits crafted MISP attribute values over the network to a MISP instance. AC:L: Injecting a single-quote character into an attribute value is trivial and requires no race conditions or special timing. AT:N: No special data manipulation or prior access to the target system is needed beyond submitting an event. PR:L: The attacker needs only basic MISP user privileges to create or modify events/attributes. UI:A: The victim analyst must actively execute the generated .sh file for the injected commands to run. VC:N, VI:N, VA:N: The MISP instance itself is not directly compromised; the impact is on the downstream system where the script executes. SC:H: The injected commands can exfiltrate fireSIGHT Manager credentials and analyst system data. SI:H: Arbitrary command execution allows modification of ACL rules, system files, or other integrity-critical resources. SA:H: Injected commands can disrupt or destroy the analyst workstation or fireSIGHT Manager availability.",
"draft": false,
"fixSummary": "All user-controlled and configuration values interpolated into the generated shell script are now passed through Python\u0027s shlex.quote() function, which produces a safely quoted string that cannot be broken out of by embedded shell metacharacters. For the JSON access-rule block that embeds multiple attribute values within a single shell assignment, the JSON content is first assembled as plain text and then the entire assembled string is shlex-quoted once, preventing stray quote characters from corrupting the outer quoting. The \u0027config\u0027 variable is now initialized to an empty dictionary before the conditional assignment, eliminating the NameError.",
"generatedAt": "2026-09-25T07:48:15.163752Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 6,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "9c34349775d058188a7b9a4d44ff873fd285faf0ddda00b46aadbaa72f3b4e6e",
"patchSummary": "Added \u0027import shlex\u0027 at the top of the module. Replaced direct .format() interpolation of config values (fmc_ip_addr, fmc_login, fmc_pass, domain_id, acpolicy_id) with shlex.quote()-wrapped values. Refactored the BLOCK_JSON_TMPL to separate the JSON content template (BLOCK_JSON_CONTENT_TMPL) from the shell assignment template; the JSON content is formatted first with raw attribute values, then the resulting string is passed through shlex.quote() before being substituted into the shell assignment. Initialized \u0027config = {}\u0027 before the \u0027if \"config\" in request:\u0027 block to prevent NameError.",
"patchTruncated": false,
"patches": [
{
"commit": "625b54908efbd6acc8343aa3370d401dd370e748",
"patchSha256": "9c34349775d058188a7b9a4d44ff873fd285faf0ddda00b46aadbaa72f3b4e6e",
"source": "https://github.com/elhoim/misp-modules/commit/625b54908efbd6acc8343aa3370d401dd370e748.patch",
"sourceUrl": "https://github.com/elhoim/misp-modules/commit/625b54908efbd6acc8343aa3370d401dd370e748.patch",
"subject": "fix: [cisco_firesight_manager_ACL_rule_export] shell-escape"
}
],
"source": "https://github.com/elhoim/misp-modules/commit/625b54908efbd6acc8343aa3370d401dd370e748.patch",
"subject": "fix: [cisco_firesight_manager_ACL_rule_export] shell-escape",
"weaknessRationale": [
{
"cweId": "CWE-78",
"rationale": "The module constructs a shell script by interpolating untrusted values (MISP attribute values, configuration fields) into single-quoted shell strings without escaping. A single-quote character in any interpolated value breaks the quoting and allows arbitrary shell command injection. This is a textbook command injection via insufficient output encoding in a generated shell script."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "gcve-1-2026-20190"
}
],
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-97863",
"datePublished": "2026-09-25T08:03:24.441Z",
"dateReserved": "2026-09-25T08:02:32.714Z",
"dateUpdated": "2026-09-25T13:19:52.508Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95806 (GCVE-0-2026-95806)
Vulnerability from cvelistv5 – Published: 2026-09-22 15:09 – Updated: 2026-09-22 15:54| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/08fa755b6 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 15:01 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/08fa755b6.patch
f4fc3223e642… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
08fa755b6363
|
chg: [internal] Unregister the phar stream wrapper in the | f4fc3223e642… |
Fix summary
The phar stream wrapper is unregistered via stream_wrapper_unregister('phar') at the top of both the web and console entry points, before any framework bootstrap or application code executes. Because no MISP component, CakePHP, or runtime library requires the phar wrapper, removing it eliminates the implicit unserialize() sink and the directory-like phar archive behavior without functional impact. This closes the deserialization and code-execution primitive application-wide, independent of whether individual callers validate their path arguments.
Patch summary
Two files are modified. In app/Console/cake.php and app/webroot/index.php, a 14-line block is inserted immediately after the file header comment and before any existing logic. The block checks whether 'phar' is present in stream_get_wrappers() and, if so, calls stream_wrapper_unregister('phar'). A docblock comment explains the security rationale: the wrapper turns filesystem calls on caller-influenced paths into unserialize() sinks and allows a relocated application root to reach code inside an uploaded file. No other code is changed; the total diff is 28 insertions across the two files.
CVSS rationale
AV:N: The vulnerability is reachable through the web entry point (app/webroot/index.php), making it network-accessible. AC:H: Exploitation requires crafting a valid phar archive with a malicious serialized payload and identifying a code path where a caller-influenced filesystem argument resolves to that archive; the commit describes this as an 'argument-injection exploit,' implying non-trivial path manipulation. AT:N: No specific attack-target conditions are indicated. PR:L: MISP is a threat-intelligence platform that typically requires authenticated access; the commit references 'the web user' context, suggesting the attacker operates within the application's privilege boundary. UI:N: No user interaction is required. VC/VI/VA:H: Successful exploitation results in arbitrary code execution as the web user, compromising confidentiality, integrity, and availability of the MISP instance. SC/SI/SA:N: No evidence of impact on subsequent or other components beyond the MISP instance itself.
Weakness rationale
- CWE-502 The phar stream wrapper causes PHP to invoke unserialize() implicitly whenever a filesystem operation resolves to a phar archive. An attacker who can influence the path argument (e.g., via argument injection) can supply a crafted phar file, triggering deserialization of attacker-controlled data and leading to code execution. This is the primary and most specific weakness.
- CWE-74 The phar stream wrapper is a special element of the PHP runtime that was not neutralized (unregistered) in the MISP entry points. Its presence allows downstream filesystem calls to be subverted into deserialization sinks. This is a secondary, broader characterization of the same issue.
Attack pattern rationale
- CAPEC-570 The core attack mechanism is that the phar stream wrapper turns a filesystem call on a caller-influenced path into an implicit unserialize() invocation. An attacker crafts a phar archive containing a malicious serialized payload and causes the application to perform a filesystem operation on that path, triggering deserialization and code execution. CAPEC-570 is the closest match. Uncertainty: the exact injection vector (which specific MISP endpoint or console command accepts the path) is not detailed in the patch, but the deserialization sink is explicitly described in the commit message.
- CAPEC-100 The phar stream wrapper is a trusted, built-in PHP component that the attacker leverages in the MISP runtime environment where it serves no legitimate purpose. The attacker does not need to exploit a flaw in the wrapper itself; rather, its mere presence in the runtime provides the primitive. This is a secondary mapping; CAPEC-570 is preferred as the primary because it more precisely describes the deserialization mechanism.
Assumptions to verify
- The affected version range is inferred from the tag_version_boundary (v2.5.47, 42 commits after fix), suggesting the fix is included in v2.5.47 and earlier versions are affected. The explicit context lists affected_version and fixed_version as null, so the exact boundary is uncertain.
- PR:L is assumed because MISP is an authenticated threat-intelligence platform; however, the patch does not explicitly state whether the vulnerable code path requires authentication. If the argument-injection vector is reachable unauthenticated, PR should be N.
- AC:H is assumed because crafting a valid phar archive and identifying the correct code path for the filesystem call is non-trivial; the commit describes it as an 'argument-injection exploit,' implying specific conditions must be met.
- The CAPEC-570 mapping is based on the commit message's explicit description of the phar wrapper as an 'unserialize() sink'; the exact MISP endpoint or console command that accepts the attacker-influenced path is not identified in the patch.
- The commit message references 'the job-argument guard reverted,' implying a prior guard existed and was removed, making the phar wrapper the remaining defense. The exact prior guard is not described in this patch.
- The Co-Authored-By line lists 'Claude Opus 5 (1M context)' as a co-author; this is recorded in the metadata as a remediation developer but is an AI assistant, not a human contributor. It is excluded from credits to avoid attributing a CVE credit to a non-human entity.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
4 | 9 | medium | 6 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95806",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:53:57.690631Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:54:08.956Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"app/Console/cake.php",
"app/webroot/index.php"
],
"product": "MISP",
"programFiles": [
"app/Console/cake.php",
"app/webroot/index.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP ships with PHP\u0027s phar stream wrapper registered in both its web entry point and its console entry point.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThe phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences:\u0026nbsp;\u2003\u003c/p\u003e\u2003-\u0026nbsp;any filesystem operation on a caller-influenced path that resolves to a phar archive triggers an implicit unserialize() call, creating a deserialization sink;\u003cbr\u003e\u003cdiv\u003e\u2003-\u0026nbsp;a relocated application root can reach executable code inside an uploaded phar file, enabling arbitrary code execution as the web user.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cp\u003eNo component of MISP, the vendored CakePHP framework, or any runtime-loaded library reads or constructs phar archives. The wrapper therefore serves no legitimate purpose in the MISP runtime and exists solely as an available primitive for an attacker who can influence a filesystem path argument.\u0026nbsp;\u003c/p\u003e"
}
],
"value": "MISP ships with PHP\u0027s phar stream wrapper registered in both its web entry point and its console entry point.\u00a0\n\nThe phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences:\u00a0\u2003\n\n\u2003-\u00a0any filesystem operation on a caller-influenced path that resolves to a phar archive triggers an implicit unserialize() call, creating a deserialization sink;\n\u2003-\u00a0a relocated application root can reach executable code inside an uploaded phar file, enabling arbitrary code execution as the web user.\n\n\n\n\nNo component of MISP, the vendored CakePHP framework, or any runtime-loaded library reads or constructs phar archives. The wrapper therefore serves no legitimate purpose in the MISP runtime and exists solely as an available primitive for an attacker who can influence a filesystem path argument."
}
],
"impacts": [
{
"capecId": "CAPEC-570",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-570 Deserialization of Untrusted Data"
}
]
},
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Leveraging Trusted Components in an Untrusted Environment"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "CWE-502 Deserialization of Untrusted Data",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:09:09.738Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/08fa755b6"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe phar stream wrapper is unregistered via stream_wrapper_unregister(\u0027phar\u0027) at the top of both the web and console entry points, before any framework bootstrap or application code executes. Because no MISP component, CakePHP, or runtime library requires the phar wrapper, removing it eliminates the implicit unserialize() sink and the directory-like phar archive behavior without functional impact. This closes the deserialization and code-execution primitive application-wide, independent of whether individual callers validate their path arguments.\u003c/p\u003e"
}
],
"value": "The phar stream wrapper is unregistered via stream_wrapper_unregister(\u0027phar\u0027) at the top of both the web and console entry points, before any framework bootstrap or application code executes. Because no MISP component, CakePHP, or runtime library requires the phar wrapper, removing it eliminates the implicit unserialize() sink and the directory-like phar archive behavior without functional impact. This closes the deserialization and code-execution primitive application-wide, independent of whether individual callers validate their path arguments."
}
],
"title": "MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influenced filesystem paths",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag_version_boundary (v2.5.47, 42 commits after fix), suggesting the fix is included in v2.5.47 and earlier versions are affected. The explicit context lists affected_version and fixed_version as null, so the exact boundary is uncertain.",
"PR:L is assumed because MISP is an authenticated threat-intelligence platform; however, the patch does not explicitly state whether the vulnerable code path requires authentication. If the argument-injection vector is reachable unauthenticated, PR should be N.",
"AC:H is assumed because crafting a valid phar archive and identifying the correct code path for the filesystem call is non-trivial; the commit describes it as an \u0027argument-injection exploit,\u0027 implying specific conditions must be met.",
"The CAPEC-570 mapping is based on the commit message\u0027s explicit description of the phar wrapper as an \u0027unserialize() sink\u0027; the exact MISP endpoint or console command that accepts the attacker-influenced path is not identified in the patch.",
"The commit message references \u0027the job-argument guard reverted,\u0027 implying a prior guard existed and was removed, making the phar wrapper the remaining defense. The exact prior guard is not described in this patch.",
"The Co-Authored-By line lists \u0027Claude Opus 5 (1M context)\u0027 as a co-author; this is recorded in the metadata as a remediation developer but is an AI assistant, not a human contributor. It is excluded from credits to avoid attributing a CVE credit to a non-human entity."
],
"capecRationale": [
{
"capecId": "CAPEC-570",
"rationale": "The core attack mechanism is that the phar stream wrapper turns a filesystem call on a caller-influenced path into an implicit unserialize() invocation. An attacker crafts a phar archive containing a malicious serialized payload and causes the application to perform a filesystem operation on that path, triggering deserialization and code execution. CAPEC-570 is the closest match. Uncertainty: the exact injection vector (which specific MISP endpoint or console command accepts the path) is not detailed in the patch, but the deserialization sink is explicitly described in the commit message."
},
{
"capecId": "CAPEC-100",
"rationale": "The phar stream wrapper is a trusted, built-in PHP component that the attacker leverages in the MISP runtime environment where it serves no legitimate purpose. The attacker does not need to exploit a flaw in the wrapper itself; rather, its mere presence in the runtime provides the primitive. This is a secondary mapping; CAPEC-570 is preferred as the primary because it more precisely describes the deserialization mechanism."
}
],
"commit": "08fa755b6363ec0b7194d97ea36800ae8eb8f919",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5 (1M context)"
}
],
"cvssRationale": "AV:N: The vulnerability is reachable through the web entry point (app/webroot/index.php), making it network-accessible. AC:H: Exploitation requires crafting a valid phar archive with a malicious serialized payload and identifying a code path where a caller-influenced filesystem argument resolves to that archive; the commit describes this as an \u0027argument-injection exploit,\u0027 implying non-trivial path manipulation. AT:N: No specific attack-target conditions are indicated. PR:L: MISP is a threat-intelligence platform that typically requires authenticated access; the commit references \u0027the web user\u0027 context, suggesting the attacker operates within the application\u0027s privilege boundary. UI:N: No user interaction is required. VC/VI/VA:H: Successful exploitation results in arbitrary code execution as the web user, compromising confidentiality, integrity, and availability of the MISP instance. SC/SI/SA:N: No evidence of impact on subsequent or other components beyond the MISP instance itself.",
"fixSummary": "The phar stream wrapper is unregistered via stream_wrapper_unregister(\u0027phar\u0027) at the top of both the web and console entry points, before any framework bootstrap or application code executes. Because no MISP component, CakePHP, or runtime library requires the phar wrapper, removing it eliminates the implicit unserialize() sink and the directory-like phar archive behavior without functional impact. This closes the deserialization and code-execution primitive application-wide, independent of whether individual callers validate their path arguments.",
"generatedAt": "2026-09-22T15:01:21.211955Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 4
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "f4fc3223e6421557e1c03c2182cfaa2b0c17a1a20870c71214708034faf1350f",
"patchSummary": "Two files are modified. In app/Console/cake.php and app/webroot/index.php, a 14-line block is inserted immediately after the file header comment and before any existing logic. The block checks whether \u0027phar\u0027 is present in stream_get_wrappers() and, if so, calls stream_wrapper_unregister(\u0027phar\u0027). A docblock comment explains the security rationale: the wrapper turns filesystem calls on caller-influenced paths into unserialize() sinks and allows a relocated application root to reach code inside an uploaded file. No other code is changed; the total diff is 28 insertions across the two files.",
"patchTruncated": false,
"patches": [
{
"commit": "08fa755b6363ec0b7194d97ea36800ae8eb8f919",
"patchSha256": "f4fc3223e6421557e1c03c2182cfaa2b0c17a1a20870c71214708034faf1350f",
"source": "https://github.com/MISP/MISP/commit/08fa755b6.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/08fa755b6.patch",
"subject": "chg: [internal] Unregister the phar stream wrapper in the"
}
],
"source": "https://github.com/MISP/MISP/commit/08fa755b6.patch",
"subject": "chg: [internal] Unregister the phar stream wrapper in the",
"tagVersionBoundary": {
"commits_after_fix": 42,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-502",
"rationale": "The phar stream wrapper causes PHP to invoke unserialize() implicitly whenever a filesystem operation resolves to a phar archive. An attacker who can influence the path argument (e.g., via argument injection) can supply a crafted phar file, triggering deserialization of attacker-controlled data and leading to code execution. This is the primary and most specific weakness."
},
{
"cweId": "CWE-74",
"rationale": "The phar stream wrapper is a special element of the PHP runtime that was not neutralized (unregistered) in the MISP entry points. Its presence allows downstream filesystem calls to be subverted into deserialization sinks. This is a secondary, broader characterization of the same issue."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20263"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95806",
"datePublished": "2026-09-22T15:09:09.738Z",
"dateReserved": "2026-09-22T15:09:04.977Z",
"dateUpdated": "2026-09-22T15:54:08.956Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95805 (GCVE-0-2026-95805)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:59 – Updated: 2026-09-22 15:53- CWE-285 - Improper Authorization
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/5ac8d1e4d | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 14:55 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/5ac8d1e4d.patch
c102952ebfab… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
5ac8d1e4dea7
|
fix: [ACL] typo in previewEventAttributes key | c102952ebfab… |
Fix summary
The fix corrects the ACL permission key for the previewEventAttributes action from the malformed string 'theming_enabled*' to the correct 'theming_enabled', restoring the intended access control restriction so that only users holding the theming_enabled permission can invoke the endpoint, consistent with the adjacent previewEventObjects entry.
Patch summary
In app/Controller/Component/ACLComponent.php (line 473), the ACL array value for the 'previewEventAttributes' key was changed from ['theming_enabled*'] to ['theming_enabled'], removing the erroneous trailing asterisk that made the permission string non-matching. One line changed, one insertion, one deletion.
CVSS rationale
AV:N: MISP is a network-accessible web application. AC:L: The vulnerability is a static typo in configuration; no race or complex condition is needed. AT:N: No attack target manipulation required. PR:L: The attacker must be an authenticated MISP user to reach the endpoint. UI:N: No victim interaction needed. VC:L: If the ACL bypass is confirmed, an unauthorized user could view event attribute data (limited confidentiality impact). VI:N and VA:N: No integrity or availability impact is evident from the patch. SC/SI/SA:N: No secondary system impact. The overall severity is Low, reflecting a single-endpoint access control misconfiguration with limited data exposure.
Weakness rationale
- CWE-285 The ACL rule for previewEventAttributes contained a typo ('theming_enabled*') that prevented the authorization check from matching the intended permission, causing the access control mechanism to not enforce the restriction as designed. This is a direct failure of the authorization logic due to a misconfigured rule.
Attack pattern rationale
- CAPEC-126 The closest plausible attack pattern is Forced Browsing, where an attacker accesses a resource (the previewEventAttributes endpoint) that should be restricted by the ACL. The typo in the ACL key may cause the authorization check to fail to deny access, effectively allowing a user without the theming_enabled permission to reach the endpoint. Uncertainty: the exact ACL evaluation behavior on a non-matching rule (default-deny vs. default-allow) is not visible in the patch, so it is also possible the typo causes a denial rather than a bypass. CAPEC-126 is selected as the best available match for an access-control bypass via misconfiguration.
Assumptions to verify
- The exact ACL evaluation behavior when a permission string does not match any valid role (default-deny vs. default-allow) is not visible in the patch; the CVSS assumes the more security-relevant interpretation (authorization bypass) but a denial-of-service interpretation is also possible.
- The affected version range is inferred from the tag boundary v2.5.47 (227 commits after the fix); the exact first affected version is not stated in the patch.
- The CAPEC-126 mapping is the closest available pattern; the actual attack is a configuration typo rather than an active browsing technique, so the mapping is approximate.
- The security impact is assumed to be limited to the previewEventAttributes endpoint; no evidence in the patch suggests other endpoints or data stores are affected.
- The CVSS assumes the endpoint exposes event attribute data viewable by unauthorized users; the actual data sensitivity depends on MISP deployment configuration.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | medium | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95805",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:53:31.726592Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:53:42.092Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"ACLComponent"
],
"product": "MISP",
"programFiles": [
"app/Controller/Component/ACLComponent.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "Thomas Lacroix"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string \u0027theming_enabled*\u0027 (with a trailing asterisk) instead of the correct \u0027theming_enabled\u0027. In the MISP ACL system, the array values define which role or permission grants access to a given controller action. The adjacent entry previewEventObjects correctly uses [\u0027theming_enabled\u0027], confirming the intended restriction. The malformed key \u0027theming_enabled*\u0027 does not match any valid permission identifier, causing the access control check for previewEventAttributes to malfunction. Depending on the ACL evaluation logic, this could result in either unauthorized users gaining access to the previewEventAttributes endpoint (authorization bypass) or legitimate users being denied access (availability impact).\u0026nbsp;\u003c/p\u003e\u003cp\u003eThe previewEventAttributes endpoint exposes event attribute data within MISP so an authorization bypass could expose sensitive indicator and attribute data to users who should not have access.\u003c/p\u003e"
}
],
"value": "A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string \u0027theming_enabled*\u0027 (with a trailing asterisk) instead of the correct \u0027theming_enabled\u0027. In the MISP ACL system, the array values define which role or permission grants access to a given controller action. The adjacent entry previewEventObjects correctly uses [\u0027theming_enabled\u0027], confirming the intended restriction. The malformed key \u0027theming_enabled*\u0027 does not match any valid permission identifier, causing the access control check for previewEventAttributes to malfunction. Depending on the ACL evaluation logic, this could result in either unauthorized users gaining access to the previewEventAttributes endpoint (authorization bypass) or legitimate users being denied access (availability impact).\u00a0\n\nThe previewEventAttributes endpoint exposes event attribute data within MISP so an authorization bypass could expose sensitive indicator and attribute data to users who should not have access."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Forced Browsing"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285 Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:59:22.041Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/5ac8d1e4d"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix corrects the ACL permission key for the previewEventAttributes action from the malformed string \u0027theming_enabled*\u0027 to the correct \u0027theming_enabled\u0027, restoring the intended access control restriction so that only users holding the theming_enabled permission can invoke the endpoint, consistent with the adjacent previewEventObjects entry.\u003c/p\u003e"
}
],
"value": "The fix corrects the ACL permission key for the previewEventAttributes action from the malformed string \u0027theming_enabled*\u0027 to the correct \u0027theming_enabled\u0027, restoring the intended access control restriction so that only users holding the theming_enabled permission can invoke the endpoint, consistent with the adjacent previewEventObjects entry."
}
],
"title": "MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restriction",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The exact ACL evaluation behavior when a permission string does not match any valid role (default-deny vs. default-allow) is not visible in the patch; the CVSS assumes the more security-relevant interpretation (authorization bypass) but a denial-of-service interpretation is also possible.",
"The affected version range is inferred from the tag boundary v2.5.47 (227 commits after the fix); the exact first affected version is not stated in the patch.",
"The CAPEC-126 mapping is the closest available pattern; the actual attack is a configuration typo rather than an active browsing technique, so the mapping is approximate.",
"The security impact is assumed to be limited to the previewEventAttributes endpoint; no evidence in the patch suggests other endpoints or data stores are affected.",
"The CVSS assumes the endpoint exposes event attribute data viewable by unauthorized users; the actual data sensitivity depends on MISP deployment configuration."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The closest plausible attack pattern is Forced Browsing, where an attacker accesses a resource (the previewEventAttributes endpoint) that should be restricted by the ACL. The typo in the ACL key may cause the authorization check to fail to deny access, effectively allowing a user without the theming_enabled permission to reach the endpoint. Uncertainty: the exact ACL evaluation behavior on a non-matching rule (default-deny vs. default-allow) is not visible in the patch, so it is also possible the typo causes a denial rather than a bypass. CAPEC-126 is selected as the best available match for an access-control bypass via misconfiguration."
}
],
"commit": "5ac8d1e4dea72f71bec3789350b748f0ad21c42c",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "Thomas Lacroix"
}
],
"cvssRationale": "AV:N: MISP is a network-accessible web application. AC:L: The vulnerability is a static typo in configuration; no race or complex condition is needed. AT:N: No attack target manipulation required. PR:L: The attacker must be an authenticated MISP user to reach the endpoint. UI:N: No victim interaction needed. VC:L: If the ACL bypass is confirmed, an unauthorized user could view event attribute data (limited confidentiality impact). VI:N and VA:N: No integrity or availability impact is evident from the patch. SC/SI/SA:N: No secondary system impact. The overall severity is Low, reflecting a single-endpoint access control misconfiguration with limited data exposure.",
"fixSummary": "The fix corrects the ACL permission key for the previewEventAttributes action from the malformed string \u0027theming_enabled*\u0027 to the correct \u0027theming_enabled\u0027, restoring the intended access control restriction so that only users holding the theming_enabled permission can invoke the endpoint, consistent with the adjacent previewEventObjects entry.",
"generatedAt": "2026-09-22T14:55:18.958107Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "c102952ebfaba16a0d028044d1bc0ab063381442b99de01bfc592144f2de9cc5",
"patchSummary": "In app/Controller/Component/ACLComponent.php (line 473), the ACL array value for the \u0027previewEventAttributes\u0027 key was changed from [\u0027theming_enabled*\u0027] to [\u0027theming_enabled\u0027], removing the erroneous trailing asterisk that made the permission string non-matching. One line changed, one insertion, one deletion.",
"patchTruncated": false,
"patches": [
{
"commit": "5ac8d1e4dea72f71bec3789350b748f0ad21c42c",
"patchSha256": "c102952ebfaba16a0d028044d1bc0ab063381442b99de01bfc592144f2de9cc5",
"source": "https://github.com/MISP/MISP/commit/5ac8d1e4d.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/5ac8d1e4d.patch",
"subject": "fix: [ACL] typo in previewEventAttributes key"
}
],
"source": "https://github.com/MISP/MISP/commit/5ac8d1e4d.patch",
"subject": "fix: [ACL] typo in previewEventAttributes key",
"tagVersionBoundary": {
"commits_after_fix": 227,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-285",
"rationale": "The ACL rule for previewEventAttributes contained a typo (\u0027theming_enabled*\u0027) that prevented the authorization check from matching the intended permission, causing the access control mechanism to not enforce the restriction as designed. This is a direct failure of the authorization logic due to a misconfigured rule."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20240"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95805",
"datePublished": "2026-09-22T14:59:22.041Z",
"dateReserved": "2026-09-22T14:59:19.797Z",
"dateUpdated": "2026-09-22T15:53:42.092Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95754 (GCVE-0-2026-95754)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:53 – Updated: 2026-09-22 15:53- CWE-285 - Improper Authentication
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/3df982ab1 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 14:51 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/3df982ab1.patch
8ddba4461463… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
3df982ab192e
|
fix: [login] Fetch User.disabled in the pre-auth TOTP lookup | 8ddba4461463… |
Fix summary
The fix adds User.disabled to the fields array of the pre-authentication find() query so that the disabled-user check in the TOTP branch reads the actual column value and correctly rejects disabled users before they reach the TOTP verification step, restoring the intended guard behavior.
Patch summary
A single-line change in app/Controller/UsersController.php appends 'User.disabled' to the fields list of the pre-authentication User find() query in the login() method (line 1385), ensuring the disabled flag is present in the result set when the TOTP branch evaluates it.
CVSS rationale
The vulnerability is reachable over the network (AV:N) via the web login endpoint with low complexity (AC:L), no attack target (AT:N), no prior privileges (PR:N), and no user interaction (UI:N). The only potential impact is a very minor confidentiality difference: a disabled, TOTP-enrolled user receives a TOTP prompt instead of an immediate rejection, which could marginally aid account-status enumeration (VC:L). There is no integrity or availability impact (VI:N, VA:N) and no secondary impacts (SC:N, SI:N, SA:N) because the subsequent identify() call still enforces the disabled-user check. The commit message explicitly characterizes the issue as 'harmless in practice.'
Weakness rationale
- CWE-285 The disabled-user check in the TOTP login branch was ineffective because the required column was not fetched, allowing a disabled user to pass that guard. The subsequent identify() call still enforced the check, limiting the impact. CWE-285 is the narrowest defensible mapping for an authentication-state check that does not function as intended.
Attack pattern rationale
- CAPEC-1 The closest plausible CAPEC is Brute Force, as the scenario involves an attacker attempting to authenticate using known credentials of a disabled, TOTP-enrolled account. The disabled-user guard that should have blocked the attempt at the TOTP branch was ineffective, allowing the attempt to proceed one step further than intended. This mapping is uncertain because the vulnerability does not enable a full authentication bypass (identify() still rejects the user) and the primary effect is a minor information-disclosure difference in the login response rather than a successful brute-force attack.
Assumptions to verify
- The commit message states the issue is 'harmless in practice' because identify() re-checks the user; this advisory treats the security impact as minimal (minor information disclosure only).
- The TOTP feature was introduced in 2023 per the commit message; the exact affected version range is not specified in the patch. The tag boundary v2.5.47 is used as an upper bound for the affected range but is not confirmed as the exact fixed version.
- CAPEC-1 (Brute Force) is the closest available attack pattern; the actual scenario is a minor authentication-guard bypass rather than a full brute-force attack, so the mapping is approximate.
- CVSS VC:L is assigned for the marginal information-disclosure difference in the login response; if the CNA determines no meaningful confidentiality impact exists, VC:N would be more appropriate, resulting in a score of 0.0.
- The PHP version behavior (Warning vs Notice vs Error for undefined array keys) may vary, but in all supported PHP versions the code continues execution with a null value, so the security analysis is unaffected.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | medium | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95754",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:53:03.966908Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:53:14.911Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"UsersController (login method",
"TOTP branch)"
],
"product": "MISP",
"programFiles": [
"app/Controller/UsersController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Fable 5.1"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn MISP\u0027s UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.totp, and User.hotp_counter. When the TOTP branch subsequently accessed $unauth_user[\u0027User\u0027][\u0027disabled\u0027], the key was absent from the result set, producing a PHP \u0027Undefined array key\u0027 warning and causing the expression to evaluate as null (falsy). As a result, the disabled-user guard in the TOTP branch was effectively a no-op: a disabled, TOTP-enrolled user could proceed to the TOTP verification step rather than being rejected at that point.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThe commit message explicitly states this was \u0027harmless in practice\u0027 because the subsequent identify() call re-validates the user and would still reject a disabled account.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThe practical security impact is therefore minimal, limited to a very small information-disclosure difference in the login response (a TOTP prompt is presented instead of an immediate rejection) and a PHP warning in application logs.\u003c/p\u003e"
}
],
"value": "In MISP\u0027s UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.totp, and User.hotp_counter. When the TOTP branch subsequently accessed $unauth_user[\u0027User\u0027][\u0027disabled\u0027], the key was absent from the result set, producing a PHP \u0027Undefined array key\u0027 warning and causing the expression to evaluate as null (falsy). As a result, the disabled-user guard in the TOTP branch was effectively a no-op: a disabled, TOTP-enrolled user could proceed to the TOTP verification step rather than being rejected at that point.\u00a0\n\nThe commit message explicitly states this was \u0027harmless in practice\u0027 because the subsequent identify() call re-validates the user and would still reject a disabled account.\u00a0\n\nThe practical security impact is therefore minimal, limited to a very small information-disclosure difference in the login response (a TOTP prompt is presented instead of an immediate rejection) and a PHP warning in application logs."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Brute Force"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:53:56.006Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/3df982ab1"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix adds User.disabled to the fields array of the pre-authentication find() query so that the disabled-user check in the TOTP branch reads the actual column value and correctly rejects disabled users before they reach the TOTP verification step, restoring the intended guard behavior.\u003c/p\u003e"
}
],
"value": "The fix adds User.disabled to the fields array of the pre-authentication find() query so that the disabled-user check in the TOTP branch reads the actual column value and correctly rejects disabled users before they reach the TOTP verification step, restoring the intended guard behavior."
}
],
"title": "MISP: Disabled-user check ineffective in pre-authentication TOTP login branch",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The commit message states the issue is \u0027harmless in practice\u0027 because identify() re-checks the user; this advisory treats the security impact as minimal (minor information disclosure only).",
"The TOTP feature was introduced in 2023 per the commit message; the exact affected version range is not specified in the patch. The tag boundary v2.5.47 is used as an upper bound for the affected range but is not confirmed as the exact fixed version.",
"CAPEC-1 (Brute Force) is the closest available attack pattern; the actual scenario is a minor authentication-guard bypass rather than a full brute-force attack, so the mapping is approximate.",
"CVSS VC:L is assigned for the marginal information-disclosure difference in the login response; if the CNA determines no meaningful confidentiality impact exists, VC:N would be more appropriate, resulting in a score of 0.0.",
"The PHP version behavior (Warning vs Notice vs Error for undefined array keys) may vary, but in all supported PHP versions the code continues execution with a null value, so the security analysis is unaffected."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The closest plausible CAPEC is Brute Force, as the scenario involves an attacker attempting to authenticate using known credentials of a disabled, TOTP-enrolled account. The disabled-user guard that should have blocked the attempt at the TOTP branch was ineffective, allowing the attempt to proceed one step further than intended. This mapping is uncertain because the vulnerability does not enable a full authentication bypass (identify() still rejects the user) and the primary effect is a minor information-disclosure difference in the login response rather than a successful brute-force attack."
}
],
"commit": "3df982ab192e05f5369d62af5674c7a874b32756",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Fable 5.1"
}
],
"cvssRationale": "The vulnerability is reachable over the network (AV:N) via the web login endpoint with low complexity (AC:L), no attack target (AT:N), no prior privileges (PR:N), and no user interaction (UI:N). The only potential impact is a very minor confidentiality difference: a disabled, TOTP-enrolled user receives a TOTP prompt instead of an immediate rejection, which could marginally aid account-status enumeration (VC:L). There is no integrity or availability impact (VI:N, VA:N) and no secondary impacts (SC:N, SI:N, SA:N) because the subsequent identify() call still enforces the disabled-user check. The commit message explicitly characterizes the issue as \u0027harmless in practice.\u0027",
"fixSummary": "The fix adds User.disabled to the fields array of the pre-authentication find() query so that the disabled-user check in the TOTP branch reads the actual column value and correctly rejects disabled users before they reach the TOTP verification step, restoring the intended guard behavior.",
"generatedAt": "2026-09-22T14:51:29.308929Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "8ddba4461463bf2e5b115b4bdd168f91b246f1fcd796dc4da8873ed8da2397c0",
"patchSummary": "A single-line change in app/Controller/UsersController.php appends \u0027User.disabled\u0027 to the fields list of the pre-authentication User find() query in the login() method (line 1385), ensuring the disabled flag is present in the result set when the TOTP branch evaluates it.",
"patchTruncated": false,
"patches": [
{
"commit": "3df982ab192e05f5369d62af5674c7a874b32756",
"patchSha256": "8ddba4461463bf2e5b115b4bdd168f91b246f1fcd796dc4da8873ed8da2397c0",
"source": "https://github.com/MISP/MISP/commit/3df982ab1.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/3df982ab1.patch",
"subject": "fix: [login] Fetch User.disabled in the pre-auth TOTP lookup"
}
],
"source": "https://github.com/MISP/MISP/commit/3df982ab1.patch",
"subject": "fix: [login] Fetch User.disabled in the pre-auth TOTP lookup",
"tagVersionBoundary": {
"commits_after_fix": 271,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-285",
"rationale": "The disabled-user check in the TOTP login branch was ineffective because the required column was not fetched, allowing a disabled user to pass that guard. The subsequent identify() call still enforced the check, limiting the impact. CWE-285 is the narrowest defensible mapping for an authentication-state check that does not function as intended."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20024"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95754",
"datePublished": "2026-09-22T14:53:56.006Z",
"dateReserved": "2026-09-22T14:53:53.341Z",
"dateUpdated": "2026-09-22T15:53:14.911Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95703 (GCVE-0-2026-95703)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:49 – Updated: 2026-09-22 15:00| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/12eaadc9e | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 14:45 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/12eaadc9e.patch
175abb34a19c… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
12eaadc9e28b
|
fix: [organisation] Reject a forged upload path in the | 175abb34a19c… |
Fix summary
The is_uploaded_file() guard is hoisted to execute immediately after the basic size/error check and before any filesystem probe (file_exists, MIME detection, EXIF reading). If the tmp_name is empty or does not correspond to a genuine PHP upload, the method returns false early, preventing any filesystem interaction with an attacker-controlled path and eliminating the information oracle.
Patch summary
In app/Controller/OrganisationsController.php, six lines are inserted inside __uploadLogo() after the existing size/error check. The added block checks whether $logo['tmp_name'] is empty or fails is_uploaded_file(), and if so, returns false immediately. A comment explains that only a genuine PHP upload may reach the subsequent filesystem probes. No other logic is modified.
CVSS rationale
AV:N: exploited over the network via the MISP web interface. AC:L: the attack is a simple parameter substitution with no race or timing requirement. AT:N: no attack-target manipulation is needed. PR:H: the commit message explicitly states this is a site-admin-only issue. UI:N: no victim interaction beyond the admin's own request. VC:L: limited confidentiality impact — disclosure of file existence and image type on the server, but no file content is read. VI:N, VA:N: no integrity or availability impact. SC:N, SI:N, SA:N: no secondary-component impact.
Weakness rationale
- CWE-200 The primary security impact is the disclosure of file existence and image type on the server through differential error messages, which constitutes sensitive information exposure to an authenticated (but not fully privileged) actor.
- CWE-20 The root cause is that the caller-supplied tmp_name value was used in filesystem operations without first validating that it originated from a genuine PHP file upload (is_uploaded_file check was performed too late or not at all before the probes).
Attack pattern rationale
- CAPEC-126 The attacker manipulates the tmp_name parameter of the upload form to point to an arbitrary server file path, causing the application to probe that path and leak information through its responses. This is the closest CAPEC pattern to the observed attack: tampering with a request parameter to trigger unintended server-side behavior. Uncertainty: no CAPEC pattern specifically covers file-existence oracles via forged upload paths, so CAPEC-126 is the best available match.
Assumptions to verify
- The commit message states the issue is 'site-admin-only'; this is taken as the required privilege level (PR:H) without independent verification of MISP's role model.
- The tag_version_boundary indicates v2.5.47 with 48 commits after the fix, suggesting the fix landed shortly after v2.5.47, but no explicit fixed version tag is provided; the affected range is therefore marked as less_than 2.5.47 with low confidence.
- The CAPEC-126 mapping is the closest available pattern; no CAPEC specifically describes a file-existence oracle via forged upload parameters, so the mapping is approximate.
- The commit message references a similar pattern in the event-report picture upload; whether that path was also fixed in this or a separate commit is not determined by this patch alone.
- The 'found during the internal review' statement in the commit message is treated as a generic internal process note; no specific finder is credited because the metadata explicitly lists finders as empty.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | medium | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95703",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T14:59:43.387710Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:00:15.086Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"OrganisationsController"
],
"product": "MISP",
"programFiles": [
"app/Controller/OrganisationsController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP file upload via is_uploaded_file. An authenticated site-admin user could supply an arbitrary server file path as the tmp_name parameter. The application would then probe that path and return distinct validation error messages depending on whether the file existed and what its image type was, effectively creating a file-existence and image-type oracle against the server filesystem.\u003c/p\u003e\u003cp\u003eThe vulnerability requires site-admin privileges and does not allow arbitrary file read, code execution, or modification; the impact is limited to disclosure of whether a given path exists on the server and, for image files, their type.\u0026nbsp;\u003c/p\u003e"
}
],
"value": "In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP file upload via is_uploaded_file. An authenticated site-admin user could supply an arbitrary server file path as the tmp_name parameter. The application would then probe that path and return distinct validation error messages depending on whether the file existed and what its image type was, effectively creating a file-existence and image-type oracle against the server filesystem.\n\nThe vulnerability requires site-admin privileges and does not allow arbitrary file read, code execution, or modification; the impact is limited to disclosure of whether a given path exists on the server and, for image files, their type."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:49:42.588Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/12eaadc9e"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe is_uploaded_file() guard is hoisted to execute immediately after the basic size/error check and before any filesystem probe (file_exists, MIME detection, EXIF reading). If the tmp_name is empty or does not correspond to a genuine PHP upload, the method returns false early, preventing any filesystem interaction with an attacker-controlled path and eliminating the information oracle.\u003c/p\u003e"
}
],
"value": "The is_uploaded_file() guard is hoisted to execute immediately after the basic size/error check and before any filesystem probe (file_exists, MIME detection, EXIF reading). If the tmp_name is empty or does not correspond to a genuine PHP upload, the method returns false early, preventing any filesystem interaction with an attacker-controlled path and eliminating the information oracle."
}
],
"title": "MISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_name",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The commit message states the issue is \u0027site-admin-only\u0027; this is taken as the required privilege level (PR:H) without independent verification of MISP\u0027s role model.",
"The tag_version_boundary indicates v2.5.47 with 48 commits after the fix, suggesting the fix landed shortly after v2.5.47, but no explicit fixed version tag is provided; the affected range is therefore marked as less_than 2.5.47 with low confidence.",
"The CAPEC-126 mapping is the closest available pattern; no CAPEC specifically describes a file-existence oracle via forged upload parameters, so the mapping is approximate.",
"The commit message references a similar pattern in the event-report picture upload; whether that path was also fixed in this or a separate commit is not determined by this patch alone.",
"The \u0027found during the internal review\u0027 statement in the commit message is treated as a generic internal process note; no specific finder is credited because the metadata explicitly lists finders as empty."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The attacker manipulates the tmp_name parameter of the upload form to point to an arbitrary server file path, causing the application to probe that path and leak information through its responses. This is the closest CAPEC pattern to the observed attack: tampering with a request parameter to trigger unintended server-side behavior. Uncertainty: no CAPEC pattern specifically covers file-existence oracles via forged upload paths, so CAPEC-126 is the best available match."
}
],
"commit": "12eaadc9e28bdb7fc723faa2f006eaaa13c4ffdb",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "AV:N: exploited over the network via the MISP web interface. AC:L: the attack is a simple parameter substitution with no race or timing requirement. AT:N: no attack-target manipulation is needed. PR:H: the commit message explicitly states this is a site-admin-only issue. UI:N: no victim interaction beyond the admin\u0027s own request. VC:L: limited confidentiality impact \u2014 disclosure of file existence and image type on the server, but no file content is read. VI:N, VA:N: no integrity or availability impact. SC:N, SI:N, SA:N: no secondary-component impact.",
"fixSummary": "The is_uploaded_file() guard is hoisted to execute immediately after the basic size/error check and before any filesystem probe (file_exists, MIME detection, EXIF reading). If the tmp_name is empty or does not correspond to a genuine PHP upload, the method returns false early, preventing any filesystem interaction with an attacker-controlled path and eliminating the information oracle.",
"generatedAt": "2026-09-22T14:45:44.315009Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "175abb34a19cd998d66ca5363124749b640d7b922547e5d3aff8bd4e4239dfa7",
"patchSummary": "In app/Controller/OrganisationsController.php, six lines are inserted inside __uploadLogo() after the existing size/error check. The added block checks whether $logo[\u0027tmp_name\u0027] is empty or fails is_uploaded_file(), and if so, returns false immediately. A comment explains that only a genuine PHP upload may reach the subsequent filesystem probes. No other logic is modified.",
"patchTruncated": false,
"patches": [
{
"commit": "12eaadc9e28bdb7fc723faa2f006eaaa13c4ffdb",
"patchSha256": "175abb34a19cd998d66ca5363124749b640d7b922547e5d3aff8bd4e4239dfa7",
"source": "https://github.com/MISP/MISP/commit/12eaadc9e.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/12eaadc9e.patch",
"subject": "fix: [organisation] Reject a forged upload path in the"
}
],
"source": "https://github.com/MISP/MISP/commit/12eaadc9e.patch",
"subject": "fix: [organisation] Reject a forged upload path in the",
"tagVersionBoundary": {
"commits_after_fix": 48,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-200",
"rationale": "The primary security impact is the disclosure of file existence and image type on the server through differential error messages, which constitutes sensitive information exposure to an authenticated (but not fully privileged) actor."
},
{
"cweId": "CWE-20",
"rationale": "The root cause is that the caller-supplied tmp_name value was used in filesystem operations without first validating that it originated from a genuine PHP file upload (is_uploaded_file check was performed too late or not at all before the probes)."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20270"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95703",
"datePublished": "2026-09-22T14:49:42.588Z",
"dateReserved": "2026-09-22T14:49:37.648Z",
"dateUpdated": "2026-09-22T15:00:15.086Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95701 (GCVE-0-2026-95701)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:44 – Updated: 2026-09-22 14:59- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/a2f7cba6e | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 14:38 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/a2f7cba6e.patch
79f69959d0bc… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
a2f7cba6e74b
|
fix: [ui] Point the org-statistics logo flag at the live | 79f69959d0bc… |
Fix summary
The fix corrects the logo directory path from the obsolete app/webroot/img/orgs to the current files/img/orgs location, expands the lookup to cover id, name, and uuid fields across png and svg extensions (mirroring the getOrgLogo helper), and adds a security guard: the candidate path is resolved with realpath() and verified via str_starts_with() against the resolved base directory, so any organization name containing traversal sequences (../) that would resolve outside files/img/orgs is rejected.
Patch summary
In app/Controller/UsersController.php __statisticsOrgs(): (1) added 'uuid' to the Organisation query fields; (2) replaced the single file_exists() call against APP/webroot/img/orgs/$k.png with a nested loop over fields [id, name, uuid] and extensions [png, svg]; (3) for each candidate, called realpath() on the full path and compared it with str_starts_with() against the realpath of the base directory (APP/files/img/orgs/), setting the logo flag only when the resolved path is confirmed to be inside that directory; (4) added a break 2 to exit both loops once a match is found.
CVSS rationale
AV:N – MISP is a network-accessible web application. AC:L – the traversal sequence in an org name is straightforward to construct. AT:N – no special target-side conditions beyond the org name being stored. PR:H – the attacker must have sufficient privileges to create or rename an organization (typically admin or org-admin role). UI:N – no user interaction required; the check fires server-side during statistics rendering. VC:L – the impact is limited to file-existence disclosure (boolean oracle); file contents are not read. VI:N, VA:N – no integrity or availability impact. SC/SI/SA:N – no secondary-system impact. Note: the vulnerability was latent in practice because the referenced directory did not exist, but the code pattern was exploitable if the directory were present or restored.
Weakness rationale
- CWE-22 The organization name (an attacker-influenced string) was concatenated directly into a file-system path for a file_exists() check without any sanitization or directory-confinement validation. The fix explicitly guards against '../' sequences escaping the intended directory, confirming the weakness is path traversal.
Attack pattern rationale
- CAPEC-1 The attack pattern involves manipulating a string value (the organization name) to inject path traversal sequences (../) that cause the application to reference files outside the intended directory. CAPEC-1 is the closest match because the core technique is crafting a string input to alter the application's file-path resolution. Uncertainty: CAPEC-126 (Leveraging Unintended Functionality) could also apply since the logo-existence check was an unintended side channel, but CAPEC-1 more directly describes the string-manipulation mechanism.
Assumptions to verify
- The affected version range is inferred from the tag_version_boundary (v2.5.47, 50 commits after fix); the exact fixed release tag is not stated in the patch metadata, so 'less_than 2.5.47' is an approximation and may need CNA confirmation.
- The vulnerability was latent in deployed instances because the referenced directory (app/webroot/img/orgs) did not exist; the CVSS reflects the code-level weakness rather than a confirmed active exploit.
- PR:H assumes that creating or renaming an organization requires elevated privileges (admin or org-admin); if MISP allows lower-privileged users to set org names, PR could be lower.
- CAPEC-1 (String Manipulation) is the closest available pattern; the exact CAPEC for path traversal via a stored string field is not explicitly enumerated in the CAPEC catalog, so this is a best-effort mapping.
- The Co-Authored-By line references an AI assistant (Claude Opus 4.8); it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | medium | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95701",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T14:59:24.647249Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:59:46.097Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"UsersController::__statisticsOrgs"
],
"product": "MISP",
"programFiles": [
"app/Controller/UsersController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image. The original code called file_exists() with a path constructed as APP . \u0027webroot\u0027 . DS . \u0027img\u0027 . DS . \u0027orgs\u0027 . DS . $k . \u0027.png\u0027, where $k is the organization name. Because the referenced directory (app/webroot/img/orgs) no longer exists in current MISP deployments (org logos were relocated to files/img/orgs), the check was functionally dead and never triggered. However, the underlying pattern\u2014concatenating an attacker-influenced organization name into a file path without sanitization\u2014constitutes a path traversal weakness. An organization name containing directory traversal sequences (e.g., \u0027../../../../etc/passwd\u0027) would, if the target directory existed, allow an authenticated user with the ability to create or rename an organization to probe for the existence of arbitrary files on the server.\u003c/p\u003e"
}
],
"value": "In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image. The original code called file_exists() with a path constructed as APP . \u0027webroot\u0027 . DS . \u0027img\u0027 . DS . \u0027orgs\u0027 . DS . $k . \u0027.png\u0027, where $k is the organization name. Because the referenced directory (app/webroot/img/orgs) no longer exists in current MISP deployments (org logos were relocated to files/img/orgs), the check was functionally dead and never triggered. However, the underlying pattern\u2014concatenating an attacker-influenced organization name into a file path without sanitization\u2014constitutes a path traversal weakness. An organization name containing directory traversal sequences (e.g., \u0027../../../../etc/passwd\u0027) would, if the target directory existed, allow an authenticated user with the ability to create or rename an organization to probe for the existence of arbitrary files on the server."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 String Manipulation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:44:21.916Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/a2f7cba6e"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix corrects the logo directory path from the obsolete app/webroot/img/orgs to the current files/img/orgs location, expands the lookup to cover id, name, and uuid fields across png and svg extensions (mirroring the getOrgLogo helper), and adds a security guard: the candidate path is resolved with realpath() and verified via str_starts_with() against the resolved base directory, so any organization name containing traversal sequences (../) that would resolve outside files/img/orgs is rejected.\u003c/p\u003e"
}
],
"value": "The fix corrects the logo directory path from the obsolete app/webroot/img/orgs to the current files/img/orgs location, expands the lookup to cover id, name, and uuid fields across png and svg extensions (mirroring the getOrgLogo helper), and adds a security guard: the candidate path is resolved with realpath() and verified via str_starts_with() against the resolved base directory, so any organization name containing traversal sequences (../) that would resolve outside files/img/orgs is rejected."
}
],
"title": "MISP Path Traversal via Organization Name in Org-Statistics Logo Check",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag_version_boundary (v2.5.47, 50 commits after fix); the exact fixed release tag is not stated in the patch metadata, so \u0027less_than 2.5.47\u0027 is an approximation and may need CNA confirmation.",
"The vulnerability was latent in deployed instances because the referenced directory (app/webroot/img/orgs) did not exist; the CVSS reflects the code-level weakness rather than a confirmed active exploit.",
"PR:H assumes that creating or renaming an organization requires elevated privileges (admin or org-admin); if MISP allows lower-privileged users to set org names, PR could be lower.",
"CAPEC-1 (String Manipulation) is the closest available pattern; the exact CAPEC for path traversal via a stored string field is not explicitly enumerated in the CAPEC catalog, so this is a best-effort mapping.",
"The Co-Authored-By line references an AI assistant (Claude Opus 4.8); it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The attack pattern involves manipulating a string value (the organization name) to inject path traversal sequences (../) that cause the application to reference files outside the intended directory. CAPEC-1 is the closest match because the core technique is crafting a string input to alter the application\u0027s file-path resolution. Uncertainty: CAPEC-126 (Leveraging Unintended Functionality) could also apply since the logo-existence check was an unintended side channel, but CAPEC-1 more directly describes the string-manipulation mechanism."
}
],
"commit": "a2f7cba6e74b791e30013f10720dadbc4117d989",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "AV:N \u2013 MISP is a network-accessible web application. AC:L \u2013 the traversal sequence in an org name is straightforward to construct. AT:N \u2013 no special target-side conditions beyond the org name being stored. PR:H \u2013 the attacker must have sufficient privileges to create or rename an organization (typically admin or org-admin role). UI:N \u2013 no user interaction required; the check fires server-side during statistics rendering. VC:L \u2013 the impact is limited to file-existence disclosure (boolean oracle); file contents are not read. VI:N, VA:N \u2013 no integrity or availability impact. SC/SI/SA:N \u2013 no secondary-system impact. Note: the vulnerability was latent in practice because the referenced directory did not exist, but the code pattern was exploitable if the directory were present or restored.",
"fixSummary": "The fix corrects the logo directory path from the obsolete app/webroot/img/orgs to the current files/img/orgs location, expands the lookup to cover id, name, and uuid fields across png and svg extensions (mirroring the getOrgLogo helper), and adds a security guard: the candidate path is resolved with realpath() and verified via str_starts_with() against the resolved base directory, so any organization name containing traversal sequences (../) that would resolve outside files/img/orgs is rejected.",
"generatedAt": "2026-09-22T14:38:57.879793Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "79f69959d0bcac7da9eea5e1dcd7edc108868ea8382a8e477d3c72e749f06a37",
"patchSummary": "In app/Controller/UsersController.php __statisticsOrgs(): (1) added \u0027uuid\u0027 to the Organisation query fields; (2) replaced the single file_exists() call against APP/webroot/img/orgs/$k.png with a nested loop over fields [id, name, uuid] and extensions [png, svg]; (3) for each candidate, called realpath() on the full path and compared it with str_starts_with() against the realpath of the base directory (APP/files/img/orgs/), setting the logo flag only when the resolved path is confirmed to be inside that directory; (4) added a break 2 to exit both loops once a match is found.",
"patchTruncated": false,
"patches": [
{
"commit": "a2f7cba6e74b791e30013f10720dadbc4117d989",
"patchSha256": "79f69959d0bcac7da9eea5e1dcd7edc108868ea8382a8e477d3c72e749f06a37",
"source": "https://github.com/MISP/MISP/commit/a2f7cba6e.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/a2f7cba6e.patch",
"subject": "fix: [ui] Point the org-statistics logo flag at the live"
}
],
"source": "https://github.com/MISP/MISP/commit/a2f7cba6e.patch",
"subject": "fix: [ui] Point the org-statistics logo flag at the live",
"tagVersionBoundary": {
"commits_after_fix": 50,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-22",
"rationale": "The organization name (an attacker-influenced string) was concatenated directly into a file-system path for a file_exists() check without any sanitization or directory-confinement validation. The fix explicitly guards against \u0027../\u0027 sequences escaping the intended directory, confirming the weakness is path traversal."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20065"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95701",
"datePublished": "2026-09-22T14:44:21.916Z",
"dateReserved": "2026-09-22T14:44:19.514Z",
"dateUpdated": "2026-09-22T14:59:46.097Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95698 (GCVE-0-2026-95698)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:36 – Updated: 2026-09-22 15:04- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/e00986075 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 14:32 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/e00986075.patch
646ef716ac7a… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
e00986075acf
|
fix: [security] Reject path traversal in the org-logo | 646ef716ac7a… |
Fix summary
The fix adds input validation in findOrgImage so that each organization identifier value (id, name, uuid) is checked to be a non-empty plain filename component. Values containing path separators (detected via basename comparison) or dot-dot sequences are rejected, preventing the constructed path from escaping the designated org-image directory. The validated value is then used in the file_exists call and the returned image reference.
Patch summary
In app/View/Helper/OrgImgHelper.php, the findOrgImage method now casts each field value to a string and rejects it if it is empty, if basename($value) does not equal $value (indicating embedded path separators), or if it contains the substring '..'. The previously unvalidated $options[$field] is replaced with the validated $value in both the file_exists() call and the assignment to $image. Ten lines added, two lines removed in a single file.
CVSS rationale
AV:N: MISP is a network-accessible web application; the org name is set via API/event import over the network. AC:L: The attacker simply includes ../ in an org name during a normal import operation; no race or complex condition is needed. AT:N: No manipulation of the target beyond normal input is required. PR:L: The attacker must be an authenticated MISP user with permission to create or import events that set the organization name. UI:N: No victim interaction is required; the traversal occurs server-side during view rendering. VC:L: The attacker gains a file-existence oracle and can read .png/.svg files outside the intended directory, a limited but real confidentiality breach. VI:N, VA:N: No integrity or availability impact is evidenced. SC:N, SI:N, SA:N: No secondary impacts are indicated by the patch or commit message.
Weakness rationale
- CWE-22 The vulnerability is a textbook path traversal: a user-controlled string (org name) is concatenated into a filesystem path without sanitization, allowing the resolved path to escape the intended directory. The fix explicitly rejects path separators and dot-dot sequences, confirming the root cause is missing path confinement.
Attack pattern rationale
- CAPEC-126 CAPEC-126 describes an attacker manipulating path components in a request to access files or directories outside the intended scope. This matches the vulnerability exactly: the org name field is manipulated to include ../ sequences, causing the server to probe and potentially read files outside the org-image directory. The mapping is direct and unambiguous.
Assumptions to verify
- The affected version boundary is inferred from the nearest git tag v2.5.47 with 51 commits after the fix; the exact last-affected and first-fixed release numbers are not explicitly stated in the patch metadata.
- PR:L assumes the attacker needs an authenticated MISP account with event-import or org-creation privileges; the patch does not specify the exact permission level required.
- The confidentiality impact is rated Low because the file read and existence oracle are limited to files with .png or .svg extensions; a broader arbitrary file read is not possible through this code path.
- CAPEC-126 is selected as the closest match; no uncertainty is noted because the attack pattern (path traversal via crafted filename) maps directly to this CAPEC entry.
- The commit date (2026-09-16) is taken at face value from the patch metadata; no independent verification of the timeline was performed.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95698",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:03:36.684296Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:04:08.199Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"app/View/Helper/OrgImgHelper.php"
],
"product": "MISP",
"programFiles": [
"app/View/Helper/OrgImgHelper.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe findOrgImage method in MISP\u0027s OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, then calls file_exists() on the resulting path. The organization name field is attacker-controllable through event import, which sets Org.name. Because no validation was performed on the field value before path construction, an organization name containing directory traversal sequences (e.g., ../../etc/passwd) would cause the path to resolve outside the intended org-image directory.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThis yields two security impacts:\u0026nbsp;\u003c/p\u003e\u2003- an arbitrary file existence oracle, since file_exists() returns a boolean for any path the process can access.\u003cbr\u003e\u003cdiv\u003e\u2003-\u0026nbsp;an arbitrary file read limited to files with .png or .svg extensions, because the resolved filename is returned and subsequently rendered or served to the requesting user.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cp\u003eThe vulnerability requires an authenticated user with the ability to create or import events that set the organization name.\u003c/p\u003e"
}
],
"value": "The findOrgImage method in MISP\u0027s OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, then calls file_exists() on the resulting path. The organization name field is attacker-controllable through event import, which sets Org.name. Because no validation was performed on the field value before path construction, an organization name containing directory traversal sequences (e.g., ../../etc/passwd) would cause the path to resolve outside the intended org-image directory.\u00a0\n\nThis yields two security impacts:\u00a0\n\n\u2003- an arbitrary file existence oracle, since file_exists() returns a boolean for any path the process can access.\n\u2003-\u00a0an arbitrary file read limited to files with .png or .svg extensions, because the resolved filename is returned and subsequently rendered or served to the requesting user.\n\n\n\n\nThe vulnerability requires an authenticated user with the ability to create or import events that set the organization name."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:36:35.043Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/e00986075"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix adds input validation in findOrgImage so that each organization identifier value (id, name, uuid) is checked to be a non-empty plain filename component. Values containing path separators (detected via basename comparison) or dot-dot sequences are rejected, preventing the constructed path from escaping the designated org-image directory. The validated value is then used in the file_exists call and the returned image reference.\u003c/p\u003e"
}
],
"value": "The fix adds input validation in findOrgImage so that each organization identifier value (id, name, uuid) is checked to be a non-empty plain filename component. Values containing path separators (detected via basename comparison) or dot-dot sequences are rejected, preventing the constructed path from escaping the designated org-image directory. The validated value is then used in the file_exists call and the returned image reference."
}
],
"title": "MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the nearest git tag v2.5.47 with 51 commits after the fix; the exact last-affected and first-fixed release numbers are not explicitly stated in the patch metadata.",
"PR:L assumes the attacker needs an authenticated MISP account with event-import or org-creation privileges; the patch does not specify the exact permission level required.",
"The confidentiality impact is rated Low because the file read and existence oracle are limited to files with .png or .svg extensions; a broader arbitrary file read is not possible through this code path.",
"CAPEC-126 is selected as the closest match; no uncertainty is noted because the attack pattern (path traversal via crafted filename) maps directly to this CAPEC entry.",
"The commit date (2026-09-16) is taken at face value from the patch metadata; no independent verification of the timeline was performed."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "CAPEC-126 describes an attacker manipulating path components in a request to access files or directories outside the intended scope. This matches the vulnerability exactly: the org name field is manipulated to include ../ sequences, causing the server to probe and potentially read files outside the org-image directory. The mapping is direct and unambiguous."
}
],
"commit": "e00986075acf47257030caa0298fad7b730a764c",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "AV:N: MISP is a network-accessible web application; the org name is set via API/event import over the network. AC:L: The attacker simply includes ../ in an org name during a normal import operation; no race or complex condition is needed. AT:N: No manipulation of the target beyond normal input is required. PR:L: The attacker must be an authenticated MISP user with permission to create or import events that set the organization name. UI:N: No victim interaction is required; the traversal occurs server-side during view rendering. VC:L: The attacker gains a file-existence oracle and can read .png/.svg files outside the intended directory, a limited but real confidentiality breach. VI:N, VA:N: No integrity or availability impact is evidenced. SC:N, SI:N, SA:N: No secondary impacts are indicated by the patch or commit message.",
"fixSummary": "The fix adds input validation in findOrgImage so that each organization identifier value (id, name, uuid) is checked to be a non-empty plain filename component. Values containing path separators (detected via basename comparison) or dot-dot sequences are rejected, preventing the constructed path from escaping the designated org-image directory. The validated value is then used in the file_exists call and the returned image reference.",
"generatedAt": "2026-09-22T14:32:54.822056Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "646ef716ac7a2ad0525154af9e0a6a7ffac9739a4f4d7114994521ae57d93fbd",
"patchSummary": "In app/View/Helper/OrgImgHelper.php, the findOrgImage method now casts each field value to a string and rejects it if it is empty, if basename($value) does not equal $value (indicating embedded path separators), or if it contains the substring \u0027..\u0027. The previously unvalidated $options[$field] is replaced with the validated $value in both the file_exists() call and the assignment to $image. Ten lines added, two lines removed in a single file.",
"patchTruncated": false,
"patches": [
{
"commit": "e00986075acf47257030caa0298fad7b730a764c",
"patchSha256": "646ef716ac7a2ad0525154af9e0a6a7ffac9739a4f4d7114994521ae57d93fbd",
"source": "https://github.com/MISP/MISP/commit/e00986075.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/e00986075.patch",
"subject": "fix: [security] Reject path traversal in the org-logo"
}
],
"source": "https://github.com/MISP/MISP/commit/e00986075.patch",
"subject": "fix: [security] Reject path traversal in the org-logo",
"tagVersionBoundary": {
"commits_after_fix": 51,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-22",
"rationale": "The vulnerability is a textbook path traversal: a user-controlled string (org name) is concatenated into a filesystem path without sanitization, allowing the resolved path to escape the intended directory. The fix explicitly rejects path separators and dot-dot sequences, confirming the root cause is missing path confinement."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20266"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95698",
"datePublished": "2026-09-22T14:36:35.043Z",
"dateReserved": "2026-09-22T14:36:33.476Z",
"dateUpdated": "2026-09-22T15:04:08.199Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95697 (GCVE-0-2026-95697)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:31 – Updated: 2026-09-22 15:06- CWE-862 - Missing Authorization
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/f3ec974ee | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 14:23 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/f3ec974ee.patch
63108ba85f58… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
f3ec974ee2d7
|
fix: [security] overwrite of org metadata by sg editors | 63108ba85f58… |
Fix summary
The fix adds an authorization check to the captureOrg method so that the forced overwrite of organization metadata fields is only permitted when the invoking user holds either the site_admin permission or the sync permission. This ensures that low-privilege roles such as sharing group editors can no longer trigger the metadata overwrite path, closing the authorization gap.
Patch summary
In app/Model/Organisation.php, the condition guarding the forced overwrite of organization metadata fields (type, date_created, date_modified, nationality, sector, contacts) was changed from a simple 'if ($force)' check to 'if ($force && (!empty($user['Role']['perm_site_admin']) || !empty($user['Role']['perm_sync'])))'. This one-line change adds a role-based authorization requirement so that only site administrators or sync-permitted users can execute the metadata overwrite when $force is true.
CVSS rationale
AV:N: MISP is a network-accessible web application. AC:L: The attack requires only calling the existing captureOrg function with $force=true; no race conditions or complex bypasses are needed. AT:N: No user interaction or attack tooling beyond normal API usage is required. PR:L: The attacker needs an authenticated account with at least SG editor privileges, which is a low-privilege role in MISP. UI:N: No victim interaction is required. VC:N: No confidentiality impact is evident from the patch. VI:H: Organization metadata (type, nationality, sector, contacts, dates) can be arbitrarily modified, representing high integrity impact on the vulnerable component. VA:N: No availability impact. SC:N: No direct confidentiality impact on other systems. SI:H: The commit message explicitly notes the issue 'could lead to blueprint based SG manipulation,' indicating integrity impact extends to sharing group configurations in the broader MISP ecosystem. SA:N: No availability impact on other systems.
Weakness rationale
- CWE-862 The captureOrg method performed a privileged operation (overwriting organization metadata) based solely on the $force flag without verifying that the authenticated user held the necessary permission (site_admin or sync). The authorization check was entirely absent for this code path, which is the definition of a missing authorization vulnerability.
Attack pattern rationale
- CAPEC-100 The closest plausible CAPEC is Parameter Tampering: an authenticated user with a lower-privilege role (SG editor) invokes the captureOrg function with the $force parameter set to true, triggering a code path that was intended only for higher-privilege users. The user manipulates a function parameter to cause unintended privileged behavior. This mapping is approximate because the core issue is a missing authorization check rather than classic parameter tampering, but no CAPEC entry more precisely describes an authenticated user exploiting a missing permission gate via a boolean flag.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.47, 139 commits after fix), suggesting the fix landed in or before v2.5.47. The exact first affected version is not specified in the patch.
- The 'blueprint based SG manipulation' impact mentioned in the commit message is taken at face value for the SI:H rating; the patch itself only shows the org metadata overwrite fix and does not include code demonstrating the SG manipulation path.
- CAPEC-100 (Parameter Tampering) is the closest available mapping; the vulnerability is more precisely a missing authorization check (CWE-862) than a classic parameter tampering scenario, but no CAPEC entry directly models 'authenticated user exploits missing permission gate via a boolean flag.'
- The PR:L rating assumes that SG editor is a low-privilege role in MISP's permission hierarchy; the patch references perm_site_admin and perm_sync as the required higher-level permissions, implying SG editor is below that level.
- No specific MISP version range is confirmed beyond the v2.5.47 tag boundary; earlier versions may or may not be affected depending on when the captureOrg method was introduced.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | medium | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95697",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:06:23.172470Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:06:43.859Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"Organisation model (app/Model/Organisation.php)"
],
"product": "MISP",
"programFiles": [
"app/Model/Organisation.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an authorization flaw in the Organisation model\u0027s captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user holds sufficient privileges. A user with a sharing group (SG) editor role can trigger this code path, allowing them to modify organization metadata that should be restricted to site administrators or users with sync permissions.\u003c/p\u003e\u003cp\u003eAccording to the commit message, this could lead to blueprint-based sharing group manipulation, meaning an attacker with SG editor access could alter organizational attributes in ways that influence how sharing groups and blueprints behave across the MISP instance.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThe vulnerability requires an authenticated user with at least SG editor privileges and network access to the MISP web interface. The impact is primarily on the integrity of organization records and, potentially, on the integrity of sharing group configurations derived from those records.\u003c/p\u003e"
}
],
"value": "MISP contains an authorization flaw in the Organisation model\u0027s captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user holds sufficient privileges. A user with a sharing group (SG) editor role can trigger this code path, allowing them to modify organization metadata that should be restricted to site administrators or users with sync permissions.\n\nAccording to the commit message, this could lead to blueprint-based sharing group manipulation, meaning an attacker with SG editor access could alter organizational attributes in ways that influence how sharing groups and blueprints behave across the MISP instance.\u00a0\n\nThe vulnerability requires an authenticated user with at least SG editor privileges and network access to the MISP web interface. The impact is primarily on the integrity of organization records and, potentially, on the integrity of sharing group configurations derived from those records."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:31:25.876Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/f3ec974ee"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix adds an authorization check to the captureOrg method so that the forced overwrite of organization metadata fields is only permitted when the invoking user holds either the site_admin permission or the sync permission. This ensures that low-privilege roles such as sharing group editors can no longer trigger the metadata overwrite path, closing the authorization gap.\u003c/p\u003e"
}
],
"value": "The fix adds an authorization check to the captureOrg method so that the forced overwrite of organization metadata fields is only permitted when the invoking user holds either the site_admin permission or the sync permission. This ensures that low-privilege roles such as sharing group editors can no longer trigger the metadata overwrite path, closing the authorization gap."
}
],
"title": "MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Metadata",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.47, 139 commits after fix), suggesting the fix landed in or before v2.5.47. The exact first affected version is not specified in the patch.",
"The \u0027blueprint based SG manipulation\u0027 impact mentioned in the commit message is taken at face value for the SI:H rating; the patch itself only shows the org metadata overwrite fix and does not include code demonstrating the SG manipulation path.",
"CAPEC-100 (Parameter Tampering) is the closest available mapping; the vulnerability is more precisely a missing authorization check (CWE-862) than a classic parameter tampering scenario, but no CAPEC entry directly models \u0027authenticated user exploits missing permission gate via a boolean flag.\u0027",
"The PR:L rating assumes that SG editor is a low-privilege role in MISP\u0027s permission hierarchy; the patch references perm_site_admin and perm_sync as the required higher-level permissions, implying SG editor is below that level.",
"No specific MISP version range is confirmed beyond the v2.5.47 tag boundary; earlier versions may or may not be affected depending on when the captureOrg method was introduced."
],
"capecRationale": [
{
"capecId": "CAPEC-100",
"rationale": "The closest plausible CAPEC is Parameter Tampering: an authenticated user with a lower-privilege role (SG editor) invokes the captureOrg function with the $force parameter set to true, triggering a code path that was intended only for higher-privilege users. The user manipulates a function parameter to cause unintended privileged behavior. This mapping is approximate because the core issue is a missing authorization check rather than classic parameter tampering, but no CAPEC entry more precisely describes an authenticated user exploiting a missing permission gate via a boolean flag."
}
],
"commit": "f3ec974ee2d72d77311dbb364c70f1aee83a58c2",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
}
],
"cvssRationale": "AV:N: MISP is a network-accessible web application. AC:L: The attack requires only calling the existing captureOrg function with $force=true; no race conditions or complex bypasses are needed. AT:N: No user interaction or attack tooling beyond normal API usage is required. PR:L: The attacker needs an authenticated account with at least SG editor privileges, which is a low-privilege role in MISP. UI:N: No victim interaction is required. VC:N: No confidentiality impact is evident from the patch. VI:H: Organization metadata (type, nationality, sector, contacts, dates) can be arbitrarily modified, representing high integrity impact on the vulnerable component. VA:N: No availability impact. SC:N: No direct confidentiality impact on other systems. SI:H: The commit message explicitly notes the issue \u0027could lead to blueprint based SG manipulation,\u0027 indicating integrity impact extends to sharing group configurations in the broader MISP ecosystem. SA:N: No availability impact on other systems.",
"fixSummary": "The fix adds an authorization check to the captureOrg method so that the forced overwrite of organization metadata fields is only permitted when the invoking user holds either the site_admin permission or the sync permission. This ensures that low-privilege roles such as sharing group editors can no longer trigger the metadata overwrite path, closing the authorization gap.",
"generatedAt": "2026-09-22T14:23:51.691782Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "63108ba85f58bd5ec8318ea052879e536aaa83464f8ff4f90ef1d386913dc835",
"patchSummary": "In app/Model/Organisation.php, the condition guarding the forced overwrite of organization metadata fields (type, date_created, date_modified, nationality, sector, contacts) was changed from a simple \u0027if ($force)\u0027 check to \u0027if ($force \u0026\u0026 (!empty($user[\u0027Role\u0027][\u0027perm_site_admin\u0027]) || !empty($user[\u0027Role\u0027][\u0027perm_sync\u0027])))\u0027. This one-line change adds a role-based authorization requirement so that only site administrators or sync-permitted users can execute the metadata overwrite when $force is true.",
"patchTruncated": false,
"patches": [
{
"commit": "f3ec974ee2d72d77311dbb364c70f1aee83a58c2",
"patchSha256": "63108ba85f58bd5ec8318ea052879e536aaa83464f8ff4f90ef1d386913dc835",
"source": "https://github.com/MISP/MISP/commit/f3ec974ee.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/f3ec974ee.patch",
"subject": "fix: [security] overwrite of org metadata by sg editors"
}
],
"source": "https://github.com/MISP/MISP/commit/f3ec974ee.patch",
"subject": "fix: [security] overwrite of org metadata by sg editors",
"tagVersionBoundary": {
"commits_after_fix": 139,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-862",
"rationale": "The captureOrg method performed a privileged operation (overwriting organization metadata) based solely on the $force flag without verifying that the authenticated user held the necessary permission (site_admin or sync). The authorization check was entirely absent for this code path, which is the definition of a missing authorization vulnerability."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20182"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95697",
"datePublished": "2026-09-22T14:31:25.876Z",
"dateReserved": "2026-09-22T14:31:23.351Z",
"dateUpdated": "2026-09-22T15:06:43.859Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95693 (GCVE-0-2026-95693)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:22 – Updated: 2026-09-22 15:09| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/9a2a4acfe | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 14:16 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/9a2a4acfe.patch
0a64cbcd6700… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
9a2a4acfe71e
|
fix: [security] Reject a forged upload path in the | 0a64cbcd6700… |
Fix summary
The fix introduces an early validation gate in EventReport::uploadPicture that checks is_uploaded_file() on the supplied tmp_name before any filesystem-probing functions (file_exists, mime_content_type, exif_imagetype) are invoked. If the value is not a genuine PHP upload, the method immediately returns a generic error message, preventing the attacker from using the endpoint as an oracle for filesystem enumeration.
Patch summary
In app/Model/EventReport.php, eight lines are inserted at the top of the upload-processing block (after the size/error check). The added code verifies that $picture['tmp_name'] is non-empty and passes is_uploaded_file(). If either condition fails, a generic 'File was not uploaded correctly' error is appended to $saveResult['errors'] and the function returns early, before pathinfo, file_exists, mime_content_type, or exif_imagetype are ever called on the untrusted path.
CVSS rationale
AV:N: MISP is a web application accessed over the network. AC:L: The attack requires only crafting a request with a different tmp_name value; no race conditions or complex setup are needed. AT:N: No prior user interaction or attack complexity beyond the request is required. PR:L: The attacker needs an authenticated account with the perm_add permission, which is a low-privilege role in MISP (not admin). UI:N: No victim interaction is required. VC:L: File existence and type information is disclosed, but file contents are not readable. VI:N, VA:N: No integrity or availability impact. SC:N, SI:N, SA:N: No impact on subsequent components.
Weakness rationale
- CWE-200 The primary security impact is the disclosure of filesystem state (file existence and type) through distinct error messages, which is a classic information exposure weakness. The attacker does not read file contents but learns metadata about arbitrary paths.
- CWE-22 The caller-supplied tmp_name was used as a filesystem path without restricting it to the upload directory. Although the impact here is information disclosure rather than full file read/write, the root cause is the lack of path restriction, making CWE-22 a contributing weakness.
Attack pattern rationale
- CAPEC-177 The attacker manipulates the tmp_name parameter to reference file paths outside the intended upload directory, causing the server to probe arbitrary locations. Although the observable effect is information disclosure rather than full file read, the mechanism is path traversal: the application uses an untrusted path string to access the filesystem. CAPEC-177 is the closest available pattern; the uncertainty is that the impact is limited to metadata disclosure rather than full traversal read, but no more specific CAPEC exists for 'path probing via error-message oracle'.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.47, 49 commits after fix), suggesting versions prior to the fix commit are vulnerable. No explicit version range is stated in the patch.
- PR:L is assumed because the commit message specifies 'any perm_add user', which is a non-admin role in MISP. The exact privilege level mapping to CVSS PR is an assumption.
- VC:L is assigned because the disclosure is limited to file existence and type metadata, not full file contents. If the information disclosed is considered more sensitive in a specific deployment, VC could be rated higher.
- CAPEC-177 (Path Traversal) is the closest available pattern; the actual impact is an information-disclosure oracle rather than a full traversal read, so the mapping is approximate.
- The Co-Authored-By line credits an AI assistant (Claude Opus 4.8) as a remediation developer. This is recorded as supplied in the metadata but is atypical for CVE credit.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | medium | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95693",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:09:40.847048Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:09:48.685Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"EventReport"
],
"product": "MISP",
"programFiles": [
"app/Model/EventReport.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP upload via is_uploaded_file(). An authenticated user holding the perm_add permission could supply an arbitrary filesystem path as the tmp_name value. The application would then probe that path and return distinct validation error messages depending on whether the file existed, its MIME type, or its image format. By observing the differing error responses, an attacker could enumerate the existence of files at arbitrary paths on the MISP server and determine their type.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThis constitutes an information disclosure vulnerability: the server\u0027s filesystem layout and file types are leaked to any user with the perm_add role without requiring administrative access.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThe vulnerability does not allow reading file contents, writing files, or executing code, but it can aid further attacks by revealing sensitive file locations (e.g., configuration files, private keys, or other artifacts) present on the host.\u003c/p\u003e"
}
],
"value": "In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP upload via is_uploaded_file(). An authenticated user holding the perm_add permission could supply an arbitrary filesystem path as the tmp_name value. The application would then probe that path and return distinct validation error messages depending on whether the file existed, its MIME type, or its image format. By observing the differing error responses, an attacker could enumerate the existence of files at arbitrary paths on the MISP server and determine their type.\u00a0\n\nThis constitutes an information disclosure vulnerability: the server\u0027s filesystem layout and file types are leaked to any user with the perm_add role without requiring administrative access.\u00a0\n\nThe vulnerability does not allow reading file contents, writing files, or executing code, but it can aid further attacks by revealing sensitive file locations (e.g., configuration files, private keys, or other artifacts) present on the host."
}
],
"impacts": [
{
"capecId": "CAPEC-177",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-177 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:22:28.896Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/9a2a4acfe"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix introduces an early validation gate in EventReport::uploadPicture that checks is_uploaded_file() on the supplied tmp_name before any filesystem-probing functions (file_exists, mime_content_type, exif_imagetype) are invoked. If the value is not a genuine PHP upload, the method immediately returns a generic error message, preventing the attacker from using the endpoint as an oracle for filesystem enumeration.\u003c/p\u003e"
}
],
"value": "The fix introduces an early validation gate in EventReport::uploadPicture that checks is_uploaded_file() on the supplied tmp_name before any filesystem-probing functions (file_exists, mime_content_type, exif_imagetype) are invoked. If the value is not a genuine PHP upload, the method immediately returns a generic error message, preventing the attacker from using the endpoint as an oracle for filesystem enumeration."
}
],
"title": "MISP Information Disclosure via Forged Upload Path",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.47, 49 commits after fix), suggesting versions prior to the fix commit are vulnerable. No explicit version range is stated in the patch.",
"PR:L is assumed because the commit message specifies \u0027any perm_add user\u0027, which is a non-admin role in MISP. The exact privilege level mapping to CVSS PR is an assumption.",
"VC:L is assigned because the disclosure is limited to file existence and type metadata, not full file contents. If the information disclosed is considered more sensitive in a specific deployment, VC could be rated higher.",
"CAPEC-177 (Path Traversal) is the closest available pattern; the actual impact is an information-disclosure oracle rather than a full traversal read, so the mapping is approximate.",
"The Co-Authored-By line credits an AI assistant (Claude Opus 4.8) as a remediation developer. This is recorded as supplied in the metadata but is atypical for CVE credit."
],
"capecRationale": [
{
"capecId": "CAPEC-177",
"rationale": "The attacker manipulates the tmp_name parameter to reference file paths outside the intended upload directory, causing the server to probe arbitrary locations. Although the observable effect is information disclosure rather than full file read, the mechanism is path traversal: the application uses an untrusted path string to access the filesystem. CAPEC-177 is the closest available pattern; the uncertainty is that the impact is limited to metadata disclosure rather than full traversal read, but no more specific CAPEC exists for \u0027path probing via error-message oracle\u0027."
}
],
"commit": "9a2a4acfe71eaacfe9305a89483d45772edf16b4",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "AV:N: MISP is a web application accessed over the network. AC:L: The attack requires only crafting a request with a different tmp_name value; no race conditions or complex setup are needed. AT:N: No prior user interaction or attack complexity beyond the request is required. PR:L: The attacker needs an authenticated account with the perm_add permission, which is a low-privilege role in MISP (not admin). UI:N: No victim interaction is required. VC:L: File existence and type information is disclosed, but file contents are not readable. VI:N, VA:N: No integrity or availability impact. SC:N, SI:N, SA:N: No impact on subsequent components.",
"fixSummary": "The fix introduces an early validation gate in EventReport::uploadPicture that checks is_uploaded_file() on the supplied tmp_name before any filesystem-probing functions (file_exists, mime_content_type, exif_imagetype) are invoked. If the value is not a genuine PHP upload, the method immediately returns a generic error message, preventing the attacker from using the endpoint as an oracle for filesystem enumeration.",
"generatedAt": "2026-09-22T14:16:43.440374Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "0a64cbcd67009e5af0b74721071bfaf4a36c3cac59e13128eaae04545009886a",
"patchSummary": "In app/Model/EventReport.php, eight lines are inserted at the top of the upload-processing block (after the size/error check). The added code verifies that $picture[\u0027tmp_name\u0027] is non-empty and passes is_uploaded_file(). If either condition fails, a generic \u0027File was not uploaded correctly\u0027 error is appended to $saveResult[\u0027errors\u0027] and the function returns early, before pathinfo, file_exists, mime_content_type, or exif_imagetype are ever called on the untrusted path.",
"patchTruncated": false,
"patches": [
{
"commit": "9a2a4acfe71eaacfe9305a89483d45772edf16b4",
"patchSha256": "0a64cbcd67009e5af0b74721071bfaf4a36c3cac59e13128eaae04545009886a",
"source": "https://github.com/MISP/MISP/commit/9a2a4acfe.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/9a2a4acfe.patch",
"subject": "fix: [security] Reject a forged upload path in the"
}
],
"source": "https://github.com/MISP/MISP/commit/9a2a4acfe.patch",
"subject": "fix: [security] Reject a forged upload path in the",
"tagVersionBoundary": {
"commits_after_fix": 49,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-200",
"rationale": "The primary security impact is the disclosure of filesystem state (file existence and type) through distinct error messages, which is a classic information exposure weakness. The attacker does not read file contents but learns metadata about arbitrary paths."
},
{
"cweId": "CWE-22",
"rationale": "The caller-supplied tmp_name was used as a filesystem path without restricting it to the upload directory. Although the impact here is information disclosure rather than full file read/write, the root cause is the lack of path restriction, making CWE-22 a contributing weakness."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20218"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95693",
"datePublished": "2026-09-22T14:22:28.896Z",
"dateReserved": "2026-09-22T14:22:26.180Z",
"dateUpdated": "2026-09-22T15:09:48.685Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95685 (GCVE-0-2026-95685)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:13 – Updated: 2026-09-22 15:13- CWE-862 - Missing Authorization
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/66aebfb1a | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-22 14:08 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/66aebfb1a.patch
4dbeb3f23f82… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
66aebfb1a1e5
|
fix: [ACL] tightening of eventreports | 4dbeb3f23f82… |
Fix summary
The ACL mapping for the replaceSuggestionInReport action was corrected from the wildcard permission ('*') to the perm_add permission, aligning it with all other report-modification actions and ensuring that only users explicitly granted the add permission can invoke the action.
Patch summary
In app/Controller/Component/ACLComponent.php, a single-line change was made in the event reports ACL array: the permission requirement for the 'replaceSuggestionInReport' key was changed from array('*') to array('perm_add'), restricting the action to users with the perm_add privilege.
CVSS rationale
The vulnerability is exploitable over the network (AV:N) via a simple HTTP request to the MISP API or web interface (AC:L). No attack target manipulation is required (AT:N). The attacker must be an authenticated user with at least basic access but without perm_add (PR:L). No user interaction is needed (UI:N). The primary impact is on the integrity of the vulnerable system's event report data (VI:H), as an unauthorized user can modify report suggestions. Confidentiality and availability impacts are not directly evidenced (VC:N, VA:N). No secondary system impact is indicated (SC:N, SI:N, SA:N).
Weakness rationale
- CWE-862 The replaceSuggestionInReport action was accessible to all authenticated users (wildcard '*') when it should have required the perm_add permission. The authorization check was effectively missing for this specific action, allowing any authenticated user to perform a privileged operation.
Attack pattern rationale
- CAPEC-126 The attacker invokes the replaceSuggestionInReport endpoint directly (e.g., via API or URL manipulation) relying on the fact that the ACL layer permits the action for all authenticated users. The attack pattern of accessing a resource or action the user is not authorized to perform by directly requesting it matches Forced Browsing. Uncertainty: the exact request vector (REST API vs. web UI) is not specified in the patch, but the underlying mechanism of bypassing intended authorization by directly calling the endpoint is consistent with this pattern.
Assumptions to verify
- The affected version range is inferred from the tag boundary (v2.5.47, 136 commits after fix); the exact last vulnerable version is not explicitly stated in the patch metadata.
- The CVSS VI:H rating assumes that modifying report suggestions constitutes a significant integrity impact on the MISP instance's threat intelligence data; if the practical impact is considered lower, VI:M may be more appropriate.
- The CAPEC-126 mapping is the closest available pattern; the exact exploitation vector (REST API call vs. web form submission) is not specified in the patch, but the core mechanism of unauthorized action invocation is consistent.
- The patch does not include the full ACLComponent context, so the exact set of users affected (e.g., whether 'perm_add' is a common or rare permission in typical MISP deployments) is not fully determinable.
- No authentication bypass is implied; the attacker must already be an authenticated MISP user.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
5 | 9 | medium | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95685",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:13:31.472359Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:13:38.313Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"EventReports",
"ACLComponent"
],
"product": "MISP",
"programFiles": [
"app/Controller/Component/ACLComponent.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly mapped to the wildcard permission (\u0027*\u0027) in the ACLComponent, making it accessible to any authenticated user regardless of their assigned permissions. All analogous report-modification actions correctly required the perm_add permission, while read-only actions such as downloadAsPDF appropriately used the wildcard.\u0026nbsp;\u003c/p\u003e\u003cp\u003eAn authenticated user without the perm_add permission could invoke the replaceSuggestionInReport endpoint to alter report suggestion data, violating the intended authorization model.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThis constitutes an improper authorization weakness that could lead to unauthorized modification of event report content, potentially corrupting shared threat intelligence data or injecting misleading information into reports relied upon by other analysts and automated consumers.\u003c/p\u003e"
}
],
"value": "MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly mapped to the wildcard permission (\u0027*\u0027) in the ACLComponent, making it accessible to any authenticated user regardless of their assigned permissions. All analogous report-modification actions correctly required the perm_add permission, while read-only actions such as downloadAsPDF appropriately used the wildcard.\u00a0\n\nAn authenticated user without the perm_add permission could invoke the replaceSuggestionInReport endpoint to alter report suggestion data, violating the intended authorization model.\u00a0\n\nThis constitutes an improper authorization weakness that could lead to unauthorized modification of event report content, potentially corrupting shared threat intelligence data or injecting misleading information into reports relied upon by other analysts and automated consumers."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Forced Browsing"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:13:26.670Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/66aebfb1a"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe ACL mapping for the replaceSuggestionInReport action was corrected from the wildcard permission (\u0027*\u0027) to the perm_add permission, aligning it with all other report-modification actions and ensuring that only users explicitly granted the add permission can invoke the action.\u003c/p\u003e"
}
],
"value": "The ACL mapping for the replaceSuggestionInReport action was corrected from the wildcard permission (\u0027*\u0027) to the perm_add permission, aligning it with all other report-modification actions and ensuring that only users explicitly granted the add permission can invoke the action."
}
],
"title": "MISP Missing Authorization on replaceSuggestionInReport Event Report Action",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag boundary (v2.5.47, 136 commits after fix); the exact last vulnerable version is not explicitly stated in the patch metadata.",
"The CVSS VI:H rating assumes that modifying report suggestions constitutes a significant integrity impact on the MISP instance\u0027s threat intelligence data; if the practical impact is considered lower, VI:M may be more appropriate.",
"The CAPEC-126 mapping is the closest available pattern; the exact exploitation vector (REST API call vs. web form submission) is not specified in the patch, but the core mechanism of unauthorized action invocation is consistent.",
"The patch does not include the full ACLComponent context, so the exact set of users affected (e.g., whether \u0027perm_add\u0027 is a common or rare permission in typical MISP deployments) is not fully determinable.",
"No authentication bypass is implied; the attacker must already be an authenticated MISP user."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The attacker invokes the replaceSuggestionInReport endpoint directly (e.g., via API or URL manipulation) relying on the fact that the ACL layer permits the action for all authenticated users. The attack pattern of accessing a resource or action the user is not authorized to perform by directly requesting it matches Forced Browsing. Uncertainty: the exact request vector (REST API vs. web UI) is not specified in the patch, but the underlying mechanism of bypassing intended authorization by directly calling the endpoint is consistent with this pattern."
}
],
"commit": "66aebfb1a1e58a82b3a681367347f69c46c38ee5",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
}
],
"cvssRationale": "The vulnerability is exploitable over the network (AV:N) via a simple HTTP request to the MISP API or web interface (AC:L). No attack target manipulation is required (AT:N). The attacker must be an authenticated user with at least basic access but without perm_add (PR:L). No user interaction is needed (UI:N). The primary impact is on the integrity of the vulnerable system\u0027s event report data (VI:H), as an unauthorized user can modify report suggestions. Confidentiality and availability impacts are not directly evidenced (VC:N, VA:N). No secondary system impact is indicated (SC:N, SI:N, SA:N).",
"fixSummary": "The ACL mapping for the replaceSuggestionInReport action was corrected from the wildcard permission (\u0027*\u0027) to the perm_add permission, aligning it with all other report-modification actions and ensuring that only users explicitly granted the add permission can invoke the action.",
"generatedAt": "2026-09-22T14:08:14.968747Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "4dbeb3f23f82f36cfdc980039b1d19717eea20a3f4d4caf25a3f0a3f72523c83",
"patchSummary": "In app/Controller/Component/ACLComponent.php, a single-line change was made in the event reports ACL array: the permission requirement for the \u0027replaceSuggestionInReport\u0027 key was changed from array(\u0027*\u0027) to array(\u0027perm_add\u0027), restricting the action to users with the perm_add privilege.",
"patchTruncated": false,
"patches": [
{
"commit": "66aebfb1a1e58a82b3a681367347f69c46c38ee5",
"patchSha256": "4dbeb3f23f82f36cfdc980039b1d19717eea20a3f4d4caf25a3f0a3f72523c83",
"source": "https://github.com/MISP/MISP/commit/66aebfb1a.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/66aebfb1a.patch",
"subject": "fix: [ACL] tightening of eventreports"
}
],
"source": "https://github.com/MISP/MISP/commit/66aebfb1a.patch",
"subject": "fix: [ACL] tightening of eventreports",
"tagVersionBoundary": {
"commits_after_fix": 136,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-862",
"rationale": "The replaceSuggestionInReport action was accessible to all authenticated users (wildcard \u0027*\u0027) when it should have required the perm_add permission. The authorization check was effectively missing for this specific action, allowing any authenticated user to perform a privileged operation."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20095"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95685",
"datePublished": "2026-09-22T14:13:26.670Z",
"dateReserved": "2026-09-22T14:13:20.760Z",
"dateUpdated": "2026-09-22T15:13:38.313Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}