MISP 2.5.28 patches multiple XSS flaws
MISP 2.5.28 fixes several cross-site scripting vulnerabilities and adds dashboard, tagging, and Meta Communities improvements to the open-source threat-intel platform.
The MISP project released version 2.5.28, a maintenance update focused primarily on security hardening and platform stability. The release patches numerous XSS vulnerabilities across the platform, including issues in the world map view, sharing group edit page, workflow execution path, and actions table element. Some of these require elevated privileges or user interaction to exploit (e.g., compromised site admin or reflected XSS requiring admin interaction), indicating limited standalone exploitability but still worth patching promptly given MISP's role hosting sensitive threat-sharing data.
Beyond security fixes, the release migrates the dashboard to Gridstack 12, refines tag filtering query logic (choosing between UNION and EXISTS query branches for performance), improves URL sanitization, and enhances the Meta Communities review process, notably vetting the CSIRT.SK MISP Community. Several functionality fixes address enrichment module error handling, proposal synchronization, galaxy cluster validation, and dependency updates including CakePHP and misp-taxonomies.
This is a routine software maintenance release rather than an active threat report. Organizations running MISP instances should apply the update to close the XSS vulnerabilities and benefit from the stability and dependency improvements, particularly given MISP's sensitive role as a threat-intelligence sharing platform.
Source reporting: https://www.misp-project.org/2025/12/11/misp.2.5.28.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free