EUVD Vulnerability Catalog

EUVD-2026-83903

Severity: MEDIUM Base Score: 6.3 CVSS Version: 4.0

Vulnerability Description

MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values to the innerHTML property. Because innerHTML parses and renders HTML markup, any untrusted string supplied as the option text (value.text or value) is interpreted as live DOM content rather than plain text. An attacker who can influence the data rendered in the contextual menu can inject arbitrary HTML or JavaScript that executes in the victim's browser within the MISP application origin. This may allow session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user. Version affected: <2.5.47

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Attack Requirements (AT): None
▪ Privileges Required (PR): Low
▪ User Interaction (UI): Passive
▪ Vulnerability Confidentiality Impact (VC): None
▪ Vulnerability Integrity Impact (VI): None
▪ Vulnerability Availability Impact (VA): None
▪ Subsequent Confidentiality Impact (SC): High
▪ Subsequent Integrity Impact (SI): High
▪ Subsequent Availability Impact (SA): None

Affected Vendors & Systems

Vendor MISP

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

CIRCL

EPSS Probability

0

Known Aliases
CVE-2026-94373 GHSA-6m7x-x7f7-6wjc
Published On

2026-09-21

Last Updated

2026-09-21