CVE-2026-88921 | MISP up to 2.5.45 MISPElementHTMLFormatterTool attribute/objectAttribute/object/tag HTML injection (949744a4b)

SecurityVulns

A vulnerability was found in MISP up to 2.5.45. It has been declared as problematic. Affected by this vulnerability is the function attribute/objectAttribute/object/tag of the component MISPElementHTMLFormatterTool. The manipulation of the argument attribute type/attribute value/object name/object relation/tag name/tag colour/tag text colour results in HTML injection.

This vulnerability is reported as CVE-2026-88921. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More