CVE-2026-103321 MISP 事件图预览存储型 XSS 漏洞
影响攻击者可在受害者浏览器中执行任意 JavaScript,窃取会话或敏感数据
MISP 的事件图预览功能存在存储型跨站脚本漏洞。事件图预览图片字段在服务端未做校验即被存储,客户端又通过字符串拼接将其渲染进 img 标签的 src 属性,导致可注入任意脚本。
影响范围
MISP 修复提交之前的版本,即 v2.5.48 及更早版本受影响。
漏洞详情
漏洞类型为存储型 XSS,成因是服务端未对事件图预览图片字段进行校验,客户端在渲染时以字符串拼接方式写入 img 元素的 src 属性,攻击者可构造特殊值突破属性上下文注入脚本。拥有创建或修改事件图条目权限的已认证用户可植入恶意载荷,当其他用户查看事件图并触发预览弹窗时脚本即被执行。
利用条件与风险
利用需攻击者具备创建或修改事件图条目的已认证权限,且需诱导受害者查看事件图并触发预览弹窗;成功后可窃取会话令牌、Cookie 或敏感数据,并以受害者身份执行操作。
修复建议
升级至包含修复提交的 MISP 版本(v2.5.48 之后);临时缓解可对事件图预览图片字段进行严格校验与转义,并在客户端避免使用字符串拼接渲染属性。
MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.
The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element’s src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.
Preconditions:
– An authenticated MISP user with the ability to create or modify an event graph entry.
– A second user (the victim) who views the event graph and triggers the preview popover.
Impact:
– Execution of arbitrary JavaScript in the victim’s browser within the MISP application context.
– Potential theft of session tokens, cookies, or sensitive data accessible to the victim’s browser.
– Potential for performing actions on behalf of the victim within the MISP application.
Affected: MISP versions prior to the fix (commit applied after v2.5.48).