CVE-2026-104906 MISP TAXII 对象查看器跨站脚本漏洞
影响攻击者可注入并执行任意 JavaScript,窃取会话令牌等敏感数据
MISP 的 TAXII 对象查看器在展示远程 TAXII 对象的字符串属性时,未对 JSON 内容进行 HTML 编码,直接渲染进 HTML pre 块中,导致跨站脚本漏洞。攻击者可通过向受害 MISP 实例订阅的 TAXII 服务器发布恶意对象来注入任意 HTML 或 JavaScript。
影响范围
MISP 2.5.48 之前的版本(Affected versions: <2.5.48)。
漏洞详情
该漏洞属于存储型/反射型跨站脚本(XSS),成因是 TAXII 对象查看器将字符串属性内容未经 HTML 编码直接输出到页面。攻击者控制 TAXII 对象内容后,可嵌入恶意脚本,当已认证用户查看该对象时脚本在 MISP 会话上下文中执行。
利用条件与风险
利用前提是受害者须为已认证 MISP 用户并访问 TAXII 对象查看器打开恶意对象;实战中可导致会话令牌、API 密钥等敏感信息泄露,并可能以受害者身份执行操作。
修复建议
官方修复方案为升级至 MISP 2.5.48 或更高版本;临时缓解措施包括避免查看不可信来源的 TAXII 对象,或对 TAXII 对象查看器输出进行 HTML 编码处理。
MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim’s MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim’s MISP session.
Preconditions:
– The victim must be an authenticated MISP user with access to the TAXII object viewer.
– The victim must open or view the crafted TAXII object.
Impact:
– Execution of arbitrary JavaScript in the victim’s browser within the MISP application context.
– Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface.
– Potential for performing actions on behalf of the authenticated user.
Affected versions: <2.5.48.